Summary
- PaperCut has confirmed customer incidents involving active exploitation against NG and MF servers.
- Huntress reproduced a pre-authentication chain that can alter trusted server configuration and lead to arbitrary Java code execution.
- PaperCut says all NG and MF versions should be treated as potentially affected while emergency fixes are deployed across supported branches.
PaperCut is responding to active attacks against its NG and MF print-management products after security researchers reproduced a pre-authentication route capable of changing trusted server configuration and reaching arbitrary code execution.
The company issued an urgent security advisory on 27 August after confirming customer incidents involving vulnerable PaperCut servers. It told organisations with application servers exposed to the public internet to restrict access immediately while its investigation and remediation work continued.
PaperCut initially treated all versions of NG and MF as potentially affected. The company also published investigation indicators including suspicious activity involving the pc-app.exe process, deleted or unexpectedly truncated server logs, and specific database errors that may appear during exploitation.
Research from Huntress subsequently provided more detail about the attack path. Its researchers reproduced a pre-authentication configuration takeover against a stock PaperCut NG installation and used the weakness to achieve remote code execution.
The flaw allows a specially crafted request to refer to one page for rendering while invoking a component belonging to another. Huntress found that PaperCut’s authorisation logic could trust the rendered page without enforcing the access requirements attached to the component behind it.
That allowed an unauthenticated request to modify server configuration. The researchers then reached functionality capable of loading attacker-controlled Java code inside the PaperCut application process.
Huntress also observed exploitation in two customer environments. In one incident, attackers executed encoded commands intended to identify the compromised user’s account and Windows version. The researchers recovered Java class files used to run commands and found evidence that logs were deleted after execution.
Those findings provide evidence of exploitation observed by Huntress, but they do not establish that every PaperCut incident has followed an identical sequence. PaperCut’s own investigation remains the authoritative source for the scope of affected product versions and the vendor’s remediation programme.
Enterprise print infrastructure can occupy a more privileged position than its name suggests. Print-management servers may connect to identity platforms, directories, databases, user endpoints, document workflows, and large fleets of networked devices.
A compromised server can consequently provide value beyond access to printing itself. Credentials, integrations, network reach, and the security context of the application process can make a print-management system useful as a platform for further activity.
Internet exposure increases that risk because exploitation no longer depends on an attacker first obtaining internal network access. PaperCut’s immediate advice to restrict public access is intended to reduce that attack surface while emergency fixes are applied.
Active exploitation also changes what constitutes a complete response. Installing a corrected version can prevent the same vulnerability being used again, but it cannot establish whether an attacker reached the system before remediation.
Organisations with exposed servers therefore have two separate questions to answer: whether the vulnerable software has been removed from reach, and whether evidence suggests it was compromised while exploitation was active.
Huntress says PaperCut has released emergency patches for supported version 25 and 26 deployments, while fixes for version 24 were still being developed at the time of its research. Administrators need to follow the vendor’s current version-specific guidance because remediation is continuing to evolve.
Neither PaperCut nor Huntress has attributed the activity to a named threat actor. The confirmed position is narrower: exploitation is occurring, customer incidents have been identified, and researchers have demonstrated that vulnerable servers can be taken from unauthenticated access to code execution.





