Cybersecurity Aug 31, 2026Add to bookmarks

PaperCut is back in the security news with a new actively exploited zero-day. The real question: why is such a widespread software so consistently neglected when it comes to patching?
PaperCut is back in security alerts. The Register reports that a new zero-day vulnerability—actively exploited—affects this print management software present in tens of thousands of organizations worldwide.
This is the latest critical alert on PaperCut in a short time. In 2023, two major flaws (CVE-2023-27350 and CVE-2023-27351) were massively exploited by ransomware groups including Clop and LockBit—in the days following their disclosure, before most administrators could react. The situation seems to be repeating itself.
PaperCut MF/NG manages printing in universities, hospitals, law firms, government agencies, and large enterprises. It's everywhere—and that's precisely the problem.
Infrastructure tools like print servers share a common fate: they are installed, configured, and never touched again. Not because IT teams are negligent, but because "if it works, don't touch it"—and printing isn't in the top 10 security priorities.
Moreover, PaperCut often has high visibility on the internal network: connection to Active Directory to authenticate users, access to printers and MFP across the entire IT system, and flows of sensitive documents. A compromised PaperCut server is a high-quality network pivot.
The pattern has become predictable:
PaperCut illustrates why patch management for "boring" tools is just as important as for core business systems—if not more so, because it is systematically deprioritized.
Action items now
- Check the official PaperCut Security Advisory: papercut.com/security – patched versions and workarounds available.
- Apply the patch urgently—do not wait for the usual maintenance window. Exploitation is active now.
- Check exposure: the PaperCut admin interface should only be accessible from trusted IPs or via VPN—never from the internet.
- Audit logs: unexpected access to the admin interface, account creations, configuration changes, or massive/unexpected print jobs.
- Consider network isolation: if you cannot patch immediately, disable remote access to the PaperCut server in the meantime.
- Plan a regular update cycle for PaperCut: this won’t be the last flaw discovered.
Article produced by artificial intelligence, reviewed under human editorial control.