Security Bulletin logo with a close up of a wolf in the background.
Security Bulletin logo with a close up of a wolf in the background.

Security Advisory: Active Exploitation of Unauthenticated Vulnerability in PaperCut NG/MF

Learn about an actively exploited PaperCut NG and MF zero-day vulnerability that could allow unauthorized code execution. Review affected versions, mitigation steps, and emergency patch guidance.
Security Bulletin logo with a close up of a wolf in the background.
6 min read

Threat Summary

PaperCut Software has issued an urgent security bulletin confirming active, zero-day exploitation of a high-severity vulnerability impacting PaperCut NG and PaperCut MF application servers. For PaperCut MF and PaperCut NG, all versions prior to Emergency Patch builds (v25, v26; v24 patch pending) are affected. Confirmed customer incidents indicate that threat actors are actively targeting public-facing PaperCut Application Servers to achieve unauthorized execution and potential remote code execution (RCE).

At the time of writing, Arctic Wolf has not identified a publicly available proof-of-concept for this specific zero-day. No public CVE has been assigned.

Organizations operating public-facing PaperCut instances must take immediate mitigating action by restricting access to trusted network ranges and applying emergency security patches released for version 25 and version 26 installations.

Recommendations

Upgrade Immediately:

PaperCut has published emergency non-standard builds for affected branches. System administrators should upgrade immediately:

  • PaperCut MF / NG (v26): Apply emergency patch v26 builds.
  • PaperCut MF / NG (v25): Apply emergency patch v25 builds.
  • PaperCut MF / NG (v24): Emergency builds are currently in development; network access restrictions must remain in place until patches are released.

Immediate priorities:

  • Remove any direct internet exposure to PaperCut Application Server web interfaces (default ports 9191/9192). Restrict access to trusted IPs or require VPN/zero trust access.
  • Apply PaperCut’s emergency patches as soon as operationally feasible, prioritizing internet-facing servers.
  • Review and harden accounts and configuration: validate admin users, rotate credentials/API keys, and audit sync/auth settings.

Workarounds

  • Network isolation: Restrict access to the PaperCut web interfaces to trusted internal networks and admin/VPN ranges; remove all direct internet exposure.
  • Reverse proxy/WAF: Place PaperCut behind an authenticated reverse proxy (SSO/MFA) with IP allowlists; block access to admin endpoints from untrusted sources.
  • Log integrity: Forward log off-host in near real time; enable file integrity monitoring to detect deletion/truncation of logs and config files.
  • Egress restrictions: Deny-by-default outbound internet access from PaperCut servers; allowlist only required vendor/licensing/update endpoints.

If no safe workaround is feasible in your environment, prioritize immediate patching and isolation.

References:

Share this post: