CVE Tools
Back to feed
Exploited in the wild PaperCut rce auth-bypass

PaperCut warns of NG, MF flaw exploited in zero-day attacks

BleepingComputer·By Lawrence Abrams··3 min read
CVE Tools coverage

PaperCut has issued an urgent advisory regarding the active exploitation of a zero-day vulnerability affecting all versions of PaperCut NG and PaperCut MF. The company confirms that customer servers are under attack and recommends immediately restricting internet exposure by limiting web interface access to trusted IP addresses. While specific technical details remain undisclosed, PaperCut has released an emergency patch for public-facing Application Servers and provided indicators of compromise, such as unusual activity in pc-app.exe processes, to help administrators detect potential breaches.