PaperCut NG and PaperCut MF (all unpatched versions)
PaperCut NG and MF are print management platforms used by universities, corporations, and governments to control and monitor printing across Canon, Epson, Xerox, Brother, and other devices.
Root Cause
The vulnerability exists in PaperCut's web management interface, which can be reached by unauthenticated external requests. An initial patch was insufficient; PaperCut worked with researchers from Huntress and watchTwr to produce a corrected fix released the following day.
Attack Vector
An attacker sends a crafted request to the exposed PaperCut web interface without needing a username or password. From there, they can take administrative control of the print server — which sits inside the corporate network and holds stored print jobs, credentials, and configuration data. Past PaperCut compromises have served as the initial foothold for ransomware deployments.
Recommended Actions
- Apply the corrected patch released Friday immediately — the first patch was insufficient
- Remove PaperCut servers from the public internet and restrict web access to trusted IP addresses only
- Check for evidence of exploitation: review server logs for unexpected authentication events or admin account changes

