PaperCut faces zero-day exploit, urging customers to patch or shut down servers
PaperCut has disclosed a zero-day flaw affecting its NG and MF print-management products and is urging users to apply an unofficial emergency fix or disconnect the web interface from the internet.
PaperCut’s security team received a report from a university that its NG and MF print-management platforms were being targeted by a zero-day attack, compromising access controls and logging. The vendor’s urgent advisory acknowledges confirmed incidents but omits technical specifics, noting that compromised systems show altered logs and alerts from intrusion-detection tools. To mitigate the risk, PaperCut has issued an untested emergency patch for customers with publicly exposed servers, while recommending that the web interface be limited to internal networks or the servers be taken offline entirely.
The company cautions that the patch has not undergone its standard release process and that a proper fix is still in development. Users must decide between applying the provisional patch or disabling the service until a validated update arrives.
Why it matters
An unpatched zero-day in widely used print-management software could let attackers infiltrate corporate networks.
In this story
