PaperCut disclosed on August 27 that its security response team is investigating active exploitation of an unpatched vulnerability in PaperCut NG and PaperCut MF, the print management software widely deployed across universities, healthcare systems, and enterprises. In an urgent security bulletin, the company said it has confirmed customer incidents and is treating the issue as its highest priority, with no CVE identifier or patch yet published as of this writing.
The advisory’s immediate guidance is blunt: any organization with a PaperCut NG/MF Application Server reachable from the public internet should restrict access to trusted IP addresses now, using firewall rules or network access controls, even without having observed suspicious activity. PaperCut said the vulnerability was surfaced through a university customer’s own security and forensics team, and it listed early indicators of compromise, including alerts tied to the application’s process activity and missing or unexpectedly truncated server log files.
The original insight is in the sequencing: PaperCut is publishing mitigation guidance before it has a root-cause fix, which is the right call for a print-management server that many IT teams treat as low priority and leave internet-facing for remote print release. That exposure pattern, similar to how CyberTech’s coverage of the Gitea flaw and the Zimbra KEV entry both showed, is exactly what turns a server nobody prioritizes into the entry point attackers rely on. Security teams running PaperCut NG or MF should act on the network-restriction guidance immediately rather than waiting for a CVE number to appear, and should treat the absence of the listed log indicators as inconclusive rather than reassuring, exactly as PaperCut itself warns.