Affected Systems
All versions of PaperCut NG and PaperCut MF print management software. Primary risk to organizations with Internet-exposed PaperCut Application Servers. PaperCut has confirmed customer incidents.
Exploitation Status
Active exploitation confirmed in the wild. PaperCut security team reproduced the vulnerability using information from a compromised University customer. No CVE assigned yet. Technical details of the flaw not disclosed.
Business Impact
Confirmed zero-day attacks against PaperCut customers with public-facing servers. Vulnerability allows compromise of Application Servers; scope of post-exploitation activity unknown (data theft, lateral movement, or ransomware deployment not yet confirmed). PaperCut historically targeted for initial access by ransomware groups including Clop, LockBit, Bl00dy, and Iranian state-backed actors. Emergency patches released but full remediation guidance pending. IOCs include suspicious pc-app.exe activity, modified/deleted server.log files, and specific JDBC-related errors in logs. Absence of IOCs does not confirm safety.
Urgency
🔴 Immediate
Recommended Actions
- Apply emergency patches immediately for all PaperCut NG/MF installations, prioritizing Internet-exposed servers
- Restrict web interface access to trusted IP addresses using firewall rules or network ACLs for all PaperCut Application Servers exposed to the Internet
- Review server.log files for indicators: suspicious pc-app.exe activity, log tampering, or errors containing 'No suitable driver found for jdbc:no:x' and 'DatabaseUtils - Database error looking up cardID: VALUES CAST'
- Assume compromise if IOCs are absent but server was Internet-exposed; conduct forensic investigation and credential rotation
- Monitor PaperCut advisory for updated IOCs and remediation steps as investigation continues
