PaperCut yet again: a new zero-day in the printing software everyone forgets to patch

Cybersecurity Aug 31, 2026Add to bookmarks

PaperCut yet again: a new zero-day in the printing software everyone forgets to patch
Illustration : Momiji Shirogane

PaperCut is back in the security news with a new actively exploited zero-day. The real question: why is such a widespread software so consistently neglected when it comes to patching?

PaperCut again: a new zero-day in the print software everyone forgets to patch

What's happening

PaperCut is back in security alerts. The Register reports that a new zero-day vulnerability—actively exploited—affects this print management software present in tens of thousands of organizations worldwide.

This is the latest critical alert on PaperCut in a short time. In 2023, two major flaws (CVE-2023-27350 and CVE-2023-27351) were massively exploited by ransomware groups including Clop and LockBit—in the days following their disclosure, before most administrators could react. The situation seems to be repeating itself.

Why PaperCut is such a recurring target

PaperCut MF/NG manages printing in universities, hospitals, law firms, government agencies, and large enterprises. It's everywhere—and that's precisely the problem.

Infrastructure tools like print servers share a common fate: they are installed, configured, and never touched again. Not because IT teams are negligent, but because "if it works, don't touch it"—and printing isn't in the top 10 security priorities.

Moreover, PaperCut often has high visibility on the internal network: connection to Active Directory to authenticate users, access to printers and MFP across the entire IT system, and flows of sensitive documents. A compromised PaperCut server is a high-quality network pivot.

The cycle that keeps repeating

The pattern has become predictable:

  1. Vulnerability discovered and disclosed
  2. Attack groups scan the internet for vulnerable instances
  3. Active exploitation within 24-72 hours
  4. Most administrators learn about the patch... too late

PaperCut illustrates why patch management for "boring" tools is just as important as for core business systems—if not more so, because it is systematically deprioritized.

What to do now

Action items now

  1. Check the official PaperCut Security Advisory: papercut.com/security – patched versions and workarounds available.
  2. Apply the patch urgently—do not wait for the usual maintenance window. Exploitation is active now.
  3. Check exposure: the PaperCut admin interface should only be accessible from trusted IPs or via VPN—never from the internet.
  4. Audit logs: unexpected access to the admin interface, account creations, configuration changes, or massive/unexpected print jobs.
  5. Consider network isolation: if you cannot patch immediately, disable remote access to the PaperCut server in the meantime.
  6. Plan a regular update cycle for PaperCut: this won’t be the last flaw discovered.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

21 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information