PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF Software
PaperCut has issued an urgent warning that attackers are actively exploiting a security flaw in its NG and MF print management software before a patch was even available. The vulnerability affects all versions of both products, which are widely used by businesses, schools, and government agencies to manage print jobs and track usage across networks.
The company has not yet detailed exactly how attackers are exploiting the flaw or what access it grants, but the zero-day status means organizations running PaperCut had no warning before exploitation began. PaperCut is urging administrators to apply available fixes and review server logs for signs of compromise.
Print management software often sits deep inside corporate networks with elevated permissions, making it an attractive target for attackers looking to move laterally or deploy ransomware.