Overview
- PaperCut published an urgent advisory saying it has confirmed customer incidents and that attackers are actively exploiting a zero-day in NG and MF, and the company released emergency patches for versions 25 and 26.
- Huntress researchers reproduced a pre-authenticated remote code execution that spawns SYSTEM-level processes and observed real attacks using base64-encoded commands, a dropped Java .class file that profiles hosts, and deletion of server logs.
- PaperCut tells customers to immediately remove public internet exposure or restrict access to trusted IPs and to preserve logs and configuration data for forensic review before remediation.
- Indicators of compromise the vendor published include suspicious activity from the legitimate pc-app.exe process, missing or truncated server.log files, and specific server.log error strings that signal possible intrusion.
- Roughly 1,000 PaperCut Application Servers remain internet-exposed, mostly in North America and Europe, and past 2023 exploits of PaperCut were used by ransomware affiliates, so attribution, full scope and a CVE are still under investigation.