Lead story
PaperCut's Zero-Day Nightmare: Attackers Are Already Inside Before the Patch Landed
If your organisation runs PaperCut NG or MF — the print management software found in universities, hospitals, government agencies, and large enterprises across Australia and globally — you need to act today. A zero-day vulnerability has been under active exploitation since before PaperCut published its emergency patch, and researchers have now confirmed that attackers are chaining two separate flaws to achieve unauthenticated remote code execution.
The first flaw is the original zero-day: an unpatched vulnerability affecting every supported version of PaperCut NG and MF that allows attackers to take control of the application's trusted configuration layer. PaperCut rushed out an emergency patch for v25 and v26, but confirmed it was already aware of "confirmed customer incidents" before the fix shipped. Then, within hours, a second advisory followed — attackers had also discovered they could chain that initial flaw with a second vulnerability in the same product family to execute arbitrary Java code inside the application server, no credentials required.
Think of it like this: the first bug hands an attacker the keys to the front door, and the second bug lets them reroute the entire building's wiring once they're inside.
PaperCut is not a niche product. It's the dominant print management platform in Australian higher education and is widely deployed across state and federal government, healthcare networks, and large corporates. The vendor's own customer list spans more than 100 million users across 70,000 organisations worldwide. Previous PaperCut vulnerabilities — most notably in 2023 — were exploited within days by ransomware groups including Clop and LockBit. That playbook is well-established, and defenders should assume the same crews are watching now.
What's different this time is the chained exploit. The combination of two bugs into a single unauthenticated RCE chain significantly lowers the bar for attackers — you don't need an insider account, a phishing foothold, or any prior access. You need a network path to the PaperCut server and a working exploit, and both appear to be circulating.
The patch situation is imperfect. PaperCut has released fixes for v25 and v26, but organisations running older supported versions have been advised to implement mitigations while waiting for patches — which, in practice, often means taking the server offline or restricting external access entirely. Neither is painless in an environment where print management is operationally critical.
For Australian organisations, the ACSC has consistently flagged PaperCut in previous exploitation waves. Given PaperCut is headquartered in Melbourne, Australian customers tend to be well-represented in the affected user base. Organisations covered by the Essential Eight should treat this as a patch-priority-one item under the "patch applications" control. Healthcare and government entities with SOCI obligations should review whether this touches any systems in scope.
Watch for: ransomware group claims in the next 48–72 hours. The 2023 PaperCut exploitation-to-ransomware window was under a week. There's no reason to expect it to be slower this time.
