

Affected Environment
PaperCut NG and PaperCut MF, all versions, print management servers exposed via web management interfaces.
Threat Overview
Two zero-days actively exploited enable arbitrary Java code execution and unauthenticated configuration changes via authentication bypass.
Exposure Timeline
Active exploitation confirmed in the wild; no official patch available yet, requiring urgent mitigation and monitoring now.
Attack Surface
PaperCut web management interface and database connection utilities, reachable by unauthenticated remote attackers over the network.
Technical Root Cause
Unsafe dynamic class loading in the database connector, plus improper access control enabling pre-authentication administrative actions.
Exploitation Pathway
Attacker manipulates driver configuration to load arbitrary Java bytecode, then deploys remote access tooling via PowerShell.
Operational Impact
Full server compromise possible, followed by remote access tool installation, credential theft, and lateral movement across networks.
Strategic Impact
Critical severity across government and business entities of all sizes given print servers' broad enterprise network reach.
Required Mitigation
Apply PaperCut mitigations immediately, monitor for indicators of compromise, and restrict access to the management interface.
Incident Response Guidance
Check server.log for listed indicators, inspect for AnyDesk or SimpleHelp remote access tooling, and isolate affected hosts.
References
PaperCut Security Bulletin, GitHub proof-of-concept repository.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




