Active Exploitation of Unnamed Zero‑Day in PaperCut NG/MF Print‑Management Software Prompts Emergency Patch
What Happened – PaperCut Software disclosed that a previously unknown zero‑day vulnerability in its NG and MF print‑management products is being actively exploited. The company issued emergency patches and urged customers to apply them immediately and to block internet‑facing access to the application servers.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unpatched critical flaws and the need for continuous vulnerability‑management evidence.
- Highlights the importance of network‑access controls that restrict public‑internet exposure of privileged application servers.
- Aligns with the control objective of timely remediation and documented proof of mitigation, which feeds audit‑readiness across multiple frameworks.
Who Is Affected – Organizations that deploy PaperCut NG or MF, spanning education, health, government, and enterprise IT environments (primarily SaaS/On‑prem print‑management customers).
Recommended Actions – Apply the emergency patches without delay, enforce firewall or network‑access‑control rules to allow only trusted IP ranges, and capture remediation evidence in your continuous control‑assurance platform.
Technical Notes – The vulnerability has no public CVE yet; indicators include suspicious activity from pc‑app.exe and tampering with server.log entries such as “ERROR No suitable driver found for jdbc:no:x”. The attack vector is a direct exploit of the software flaw, followed by log manipulation to evade detection.
Source: Security Affairs