PaperCut Rolls Out Full Fix for Two Print-Server Flaws Already Under Attack

The vendor replaced its earlier emergency patches with proper maintenance releases across three supported branches.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal close-up of a darkened server rack with one blade pulled partially out, glowing amber status LEDs reflecting off the brushed-m
Share

Key points

  • PaperCut released maintenance updates 26.0.5, 25.0.13 and 24.1.10 on Thursday, replacing earlier emergency hotfixes.
  • The updates fix two vulnerabilities in PaperCut NG/MF that attackers are already exploiting in the wild.
  • Print-management servers often sit on internal networks with wide access, which makes them a useful stepping stone for intruders.
  • Customers who applied the earlier emergency patches still need to install the new maintenance release.
  • PaperCut software runs in schools, hospitals, law firms and government offices around the world.

PaperCut has published a proper fix for two security flaws in its print-management software that criminals are already using to break into networks. The new releases replace the emergency hotfixes the company rushed out earlier and roll the changes into its normal update track.

The updated versions are PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10, released Thursday. PaperCut NG and PaperCut MF are the products that thousands of organisations use to manage office printing: tracking who prints what, charging for pages, and holding print jobs until a user taps a card at the machine.

If that sounds boring, the servers behind it are not. A print server usually sits deep inside a company network and talks to almost every workstation. Break into one, and you have a comfortable place to look around from.

What are the two flaws?

They are two separate security holes in PaperCut NG/MF that attackers are actively exploiting, meaning real intrusions are happening now, not just theoretical ones. PaperCut has not published deep technical detail, which is normal while customers are still patching.

The company first shipped what it called emergency patches, small targeted fixes released outside the usual schedule. Those held the line but were not a long-term answer. Thursday's release, first reported by The Hacker News, folds the fixes into the standard maintenance branches, so administrators no longer have to track a separate hotfix on top of their regular version.

Who needs to act, and how fast?

Any organisation running PaperCut NG or PaperCut MF on-premises should install the new maintenance release now, even if they already applied the earlier emergency patch. Cloud-hosted PaperCut customers are updated by the vendor.

Here is how the versions line up:

Branch Fixed version Replaces
26.x 26.0.5 Earlier emergency patch
25.x 25.0.13 Earlier emergency patch
24.x 24.1.10 Earlier emergency patch

Administrators should also check whether their PaperCut admin console is reachable from the public internet. It usually should not be. Restricting the admin interface to an internal network or a VPN cuts off the easiest path an attacker would take.

Does this affect ordinary people?

Not directly. There is no consumer app to update and no password to change. The people who need to act are the IT teams that run print services inside schools, hospitals, councils and companies.

That said, PaperCut has a history worth remembering. In 2023, a different set of flaws in the same product was used by ransomware crews, criminals who lock a company's files and demand payment, to get inside education and healthcare networks. Print servers being humble does not make them safe.

On the authentication side, and this is my usual note: multi-factor authentication, the extra code or tap on your phone after a password, would not have stopped exploitation of a server-side flaw like this one. This is a patching problem, not a login problem. The fix is to install the update.

Common questions

I use PaperCut at work. Do I need to do anything?

No. Your IT team handles the server update. You do not need to change your printing PIN or card.

Is my print history exposed?

PaperCut has not said the flaws leak print job contents. The immediate risk is attackers using the server as a foothold to reach other systems on the network.

© 2026 Threat Vectr