Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
- ID
- 18938
- Status
- summarized
- Published
- 28 Aug 2026, 1:29 PM
- Fetched
- 28 Aug 2026, 3:23 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/28/print-management-outfit-papercut-is-under-0-day-attack-and-its-drawing-customers-blood/5293168
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 28 Aug 2026, 3:24 PM
- Tags
- Audience
- developers
What happened
PaperCut's print management products (PaperCut NG and PaperCut MF) are under active zero-day attack after a university security team reported incidents. The company released an unofficial emergency patch that bypassed its normal release process, but advises customers to either restrict web interface access to trusted internal IPs or take servers offline entirely. The advisory is unusually silent on the nature of the flaw, though indicators of compromise include altered log files and alerts from IDS/endpoint/network monitoring tools.
Why it matters
If you run PaperCut NG or MF with a web interface exposed to the public internet, restrict it to trusted internal IPs immediately—this is the primary mitigation and is trivial to implement. The broader lesson: any admin web interface left internet-facing is a liability, and an unofficial patch from a vendor under pressure is not a fix you want to rely on in production.
Discussion angle
The tradeoff between vendors releasing rushed unofficial patches versus simply telling customers to take systems offline—when is an unvalidated patch worse than downtime, and how should teams decide?