Zero‑Day Vulnerability in PaperCut NG & MF Print Management Software Actively Exploited
What Happened — PaperCut disclosed that a zero‑day flaw affecting all versions of its PaperCut NG and PaperCut MF print‑management suites is being weaponised in the wild. The vendor issued emergency patches for the v25 and v26 branches and confirmed that at least one customer has been impacted.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a control‑gap scenario that SOC 2 Change Management (CC6.1) and Vulnerability Management (CC7.2) are designed to detect, remediate, and evidence.
- Continuous evidence of third‑party patching and remediation is essential to demonstrate due diligence during a SOC 2 audit.
- Mapping this vulnerability to your control framework and retaining audit‑ready proof of remediation reduces audit‑finding risk and supports a defensible trust posture.
Who Is Affected — Organizations that rely on PaperCut NG or MF for print management across any sector (e.g., education, healthcare, finance, and enterprise IT).
Recommended Actions
- Immediately apply the emergency patches for v25/v26 and verify that all endpoints are updated.
- Record patch‑deployment dates, affected assets, and validation results in a centralized compliance repository.
- Integrate PaperCut into your continuous vulnerability‑scanning program and map the finding to SOC 2 CC6.1/CC7.2 controls.
- Update incident‑response playbooks to include print‑service exploitation scenarios.
Technical Notes — The flaw is a remote code execution (RCE) path triggered via malformed print‑job data; no CVE ID has been published yet. Attackers are exploiting it over the network to gain execution on print‑server hosts. Source: The Hacker News