Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities in PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog, confirming attackers are actively using them in real-world attacks. The flaws include a missing authentication issue that could let attackers bypass login controls, and an unsafe reflection vulnerability that could allow malicious code execution.
PaperCut is widely used by businesses, schools, and government agencies to manage networked printing, meaning many organisations - including Australian small and medium businesses - may have it deployed without realising it's a target. Because these vulnerabilities allow attackers to gain unauthorised access or control, unpatched systems exposed to the internet are at serious risk of compromise, data theft, or being used as a foothold for further attacks.
While CISA's directive formally applies to US federal agencies, the underlying message applies to everyone: vulnerabilities listed in the KEV catalog are proven to be exploited in the wild, not just theoretical risks. Any business running PaperCut NG or MF should treat this as a priority patching issue rather than routine maintenance.