Hackers Actively Exploiting Pre-Auth RCE Flaw in PaperCut Print Software
Brief
Attackers are actively exploiting a critical, unauthenticated remote code execution (RCE) vulnerability in PaperCut NG and PaperCut MF, widely used print management software, security researchers at Huntress have confirmed .
The flaw allows an attacker to remotely take control of a PaperCut server’s configuration without needing any login credentials, ultimately enabling arbitrary code execution on the underlying system. PaperCut published an “urgent security advisory” on 27 August, warning customers that the vulnerability was being exploited in the wild, and has since released emergency patches for versions 25 and 26 of both products.
A fix for version 24 is still in progress, and the vendor is treating all NG and MF versions as potentially affected.
Confirmed exploitation in the wild
Huntress said it has observed exploitation of the flaw across two customer environments.
