PaperCut has alerted its users about an active exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. This zero-day vulnerability has prompted the company to release an emergency patch for versions 25 and 26 to mitigate the risk. PaperCut has confirmed that several customers have already been affected and is prioritizing the issue with an ongoing investigation to understand the full extent of the breach.
Currently, there are no specific details available about the nature of the vulnerability, the method of exploitation, or the identity of the attackers. However, PaperCut advises users who have their PaperCut NG or MF Application Server exposed to the internet to restrict access immediately to trusted IP addresses only. This can be achieved through firewall rules, network access controls, or other equivalent security measures to prevent unauthorized access to the server's web interfaces.
This incident draws parallels to a previous critical flaw in 2023, identified as CVE-2023-27350 with a CVSS score of 9.8, which was exploited by Russian threat actors and the hacking group Lace Tempest. They used the vulnerability to deploy Cl0p and LockBit ransomware. As this situation develops, organizations using PaperCut software are urged to apply the emergency patch and continuously monitor for any signs of suspicious activity.


