Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login
Security researchers have found that malicious actors are actively exploiting a newly patched flaw in PaperCut NG and MF, popular print management software used by businesses worldwide. The vulnerability allows an unauthenticated attacker to remotely take control of PaperCut's trusted configuration settings, which can then be abused to run arbitrary Java code inside the application. In response, PaperCut has released an emergency fix that adds further hardening beyond the initial patch.
This type of vulnerability chain is particularly dangerous because it removes the need for stolen passwords or insider access — an attacker simply needs network access to a vulnerable, internet-facing PaperCut server to gain a foothold. Once inside, attackers could potentially deploy further malware, steal data, or move deeper into a company's network.
Any business using PaperCut NG or MF for print management should treat this as a high-priority update. Given that PaperCut is widely deployed in offices, schools, and government agencies, unpatched systems represent an attractive and easy target for opportunistic attackers scanning the internet for vulnerable servers.