PaperCut Zero‑Day Exploited in NG/MF Print Management Products – Emergency Patch Issued
What Happened — PaperCut Software disclosed that a previously unknown zero‑day vulnerability in its NG and MF print‑management applications is being actively exploited. The vendor released emergency patches on Friday and warned customers to isolate the application servers from the public Internet.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a control gap in Change Management and System Operations (SOC 2 CC6.1/CC3.1) where unpatched software can become an attack vector.
- Continuous evidence of patch‑management, network‑segmentation, and firewall rule enforcement is essential to demonstrate due diligence during a SOC 2 audit.
- Verisq’s Control Mapping capability can automatically map the emergency‑patch process to the relevant SOC 2 controls and collect immutable proof for auditors.
Who Is Affected — Organizations that deploy PaperCut NG/MF for print management across any sector (education, health, finance, government, etc.).
Recommended Actions
- Apply the emergency patches immediately.
- Restrict PaperCut application‑server web access to trusted IP ranges via firewall or network‑access‑control lists.
- Document the patch‑deployment workflow and update your change‑management records to reflect the emergency response.
- Enable continuous monitoring of the server logs for the IOC patterns listed in the advisory.
Source: Security Affairs
Technical Notes
- No CVE identifier assigned yet; the flaw affects PaperCut NG and MF servers.
- Attackers have been observed deleting or truncating
server.logentries and injecting malformed JDBC error strings. - Indicators of compromise include suspicious activity from
pc‑app.exeand log entries such asERROR No suitable driver found for jdbc:no:x.