Particle.news

PaperCut Zero-Day Under Active Exploitation, Vendor Issues Emergency Patches

The flaw allows unauthenticated attackers to run code as the PaperCut server’s SYSTEM user, raising the risk of wider network intrusion if exposed servers are not isolated or patched.

Overview

  • PaperCut published an urgent advisory saying it has confirmed customer incidents and that attackers are actively exploiting a zero-day in NG and MF, and the company released emergency patches for versions 25 and 26.
  • Huntress researchers reproduced a pre-authenticated remote code execution that spawns SYSTEM-level processes and observed real attacks using base64-encoded commands, a dropped Java .class file that profiles hosts, and deletion of server logs.
  • PaperCut tells customers to immediately remove public internet exposure or restrict access to trusted IPs and to preserve logs and configuration data for forensic review before remediation.
  • Indicators of compromise the vendor published include suspicious activity from the legitimate pc-app.exe process, missing or truncated server.log files, and specific server.log error strings that signal possible intrusion.
  • Roughly 1,000 PaperCut Application Servers remain internet-exposed, mostly in North America and Europe, and past 2023 exploits of PaperCut were used by ransomware affiliates, so attribution, full scope and a CVE are still under investigation.