PaperCut has released a second emergency security update for its widely used NG and MF print management software after confirming that attackers are actively exploiting vulnerabilities in customer environments.
The incident involves two newly disclosed security flaws, including a critical vulnerability rated 9.4 out of 10. Researchers say the weaknesses can be chained to move from unauthenticated access to code execution on vulnerable PaperCut servers, increasing the risk for organizations that expose their management interfaces to the public internet.
Emergency Patch Release 2 was issued after further security analysis found that additional hardening was needed beyond the company’s first emergency fix. The latest patch is available for PaperCut NG and MF versions 24, 25 and 26, while organizations running older releases are being advised to upgrade to a supported version.
PaperCut has also expanded its list of indicators linked to observed attacks, including suspicious activity launched by the PaperCut server process, altered or missing log files, unusual database activity and the deployment of remote access tools on compromised systems.
The investigation remains active, with PaperCut engineers working on a full software release while new technical details continue to emerge. Administrators are being urged to restrict access to internet-facing PaperCut servers, install the latest emergency patch and examine affected systems for signs that attackers may already have gained access.

Leave a Reply