PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

Summary

PaperCut has issued an alert regarding a zero-day vulnerability actively being exploited in its PaperCut NG and PaperCut MF print management software. The company has released an emergency patch for versions v25 and v26 to address the critical issue, acknowledging confirmed customer incidents.

IFF Assessment

FOE

The active exploitation of a zero-day vulnerability in critical print management software represents a significant threat to organizations, allowing attackers to compromise systems.

Severity

9.8 Critical (AI Estimated)

Given that this is a zero-day vulnerability being actively exploited in a widely used print management system, it is highly likely to have a high CVSS score (e.g., Critical or High) due to its potential for widespread impact and ease of exploitation, potentially allowing for remote code execution or unauthorized access.

Defender Context

Organizations using PaperCut NG or MF should prioritize applying the emergency patch immediately to mitigate the risk of exploitation. This incident highlights the importance of timely patching for critical infrastructure and the ongoing threat posed by zero-day exploits targeting common software.

Read Full Story →