PaperCut zero-day attacks are exploiting an undisclosed vulnerability in PaperCut NG and PaperCut MF, prompting the vendor to release emergency patches on August 28. PaperCut said it knows of confirmed customer incidents and that every version of both print-management products is potentially affected.

The company published its initial alert on August 27 and updated it after reproducing the vulnerability with information from a university customer, its security team and digital-forensics responders. BleepingComputer independently reported the active attacks. PaperCut has not disclosed a CVE identifier, vulnerability class, severity score, attacker identity or verified post-compromise objective.

PaperCut advised organizations to immediately prevent untrusted internet addresses from reaching Application Server web interfaces. Administrators should use firewall rules, network access controls or equivalent measures to limit access to trusted internal addresses, even when they have found no suspicious activity. The vendor said the investigation remains in progress.

Potential indicators include security alerts showing suspicious post-exploitation activity from the legitimate pc-app.exe process and server.log files that are missing, deleted or unexpectedly truncated. PaperCut also told defenders to check server.log for the errors ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST. It cautioned that finding none of these signs does not prove a server is clean.

Emergency patch packages are available for PaperCut NG and MF versions 25 and 26 on Windows, Linux and macOS, with SHA-256 checksums in the vendor bulletin. PaperCut described them as emergency builds that have not completed its normal release process. Version 24 builds remain in progress, and patched systems using external Card or ID database lookups can no longer run queries containing EXEC, EXECUTE or CALL.

Administrators should first remove public exposure where possible, apply the appropriate emergency package when isolation is not practical, preserve and review relevant logs, and investigate any listed indicator through established incident-response procedures. Because technical details and validated impact remain limited, defenders should continue monitoring the PaperCut bulletin for updated remediation and compromise guidance.