# PaperCut's Printer Problem Returns: Zero-Days Weaponized for Data Theft Before Most Teams Even Knew to Patch


Print management software is not where most security teams spend their time. That's exactly why attackers keep going back to it.


Two zero-day vulnerabilities in PaperCut NG and MF were patched last week — and threat actors had already beaten the fix. They are now being actively used in data theft campaigns, according to fresh threat intelligence. For organizations running PaperCut across campus networks, government offices, and corporate print floors, the window between "we know about this" and "we got hit" has effectively closed.


## The Vulnerability Landscape


PaperCut NG and MF are ubiquitous in environments that print at scale: universities, hospitals, law firms, local governments, managed print service providers. The software handles authentication, quota management, and user tracking — it sits at an interesting intersection of identity and infrastructure.


The newly patched flaws were exploited as zero-days, meaning attackers had working exploits before PaperCut shipped a fix. That's a significant qualifier. A zero-day exploitation window tells you something about who was doing this — opportunists don't typically invest in zero-day development. Targeted actors do.


The campaigns now using these vulnerabilities are focused on data exfiltration. That points away from ransomware pre-positioning (at least for now) and toward intelligence gathering or credential harvesting — though the two are rarely mutually exclusive for long.


## PaperCut Has Been Here Before


This is not PaperCut's first incident of this magnitude, and that context matters enormously.


In spring 2023, CVE-2023-27350 — a critical authentication bypass in PaperCut — was weaponized within days of public disclosure. The Clop ransomware gang and LockBit affiliates both moved on it. CISA added it to the Known Exploited Vulnerabilities catalog. Thousands of exposed servers were targeted globally. Education and government sectors took disproportionate hits.


The 2023 wave should have prompted a hard conversation inside every PaperCut deployment about network segmentation, patching velocity, and whether print management servers need internet exposure at all. That conversation apparently did not fully land, because here we are again.


Print management software occupies a privileged position that is easy to overlook. PaperCut servers typically hold user credentials, can interact with Active Directory, and process documents that transit across the entire organization. That is not a low-value target. It is, in fact, an excellent pivot point — and attackers have demonstrated twice now that they know it.


## Who Is Actually at Risk


The realistic exposure map skews toward a few specific sectors:


Higher education runs PaperCut extensively for student printing quotas. University networks are notoriously flat and under-resourced for security, and PaperCut servers frequently have broader network access than they need. These environments also tend to lag on patching cadence.


K-12 school districts face a similar structural problem — centralized print management, minimal security staffing, and software that rarely gets the scrutiny applied to endpoint or identity systems.


Managed print service providers are a multiplier risk. If an MPS firm manages PaperCut deployments for dozens of client organizations and their own infrastructure is compromised, the blast radius extends well beyond a single victim.


Government agencies at state and local levels are consistent PaperCut users. Many operate under procurement constraints that delay patching cycles.


The common thread: organizations that run PaperCut often run it without treating it as a security-critical system. That assumption is now clearly wrong.


## What Patching Actually Requires Here


Applying the PaperCut patches is necessary but not sufficient.


If these zero-days were being exploited before the patches were released, some number of organizations were already compromised when the fix dropped. Patching closes the door but does not evict anyone already inside. Incident response and threat hunting matter here — looking for anomalous outbound connections, unusual access to document queues, or credential material being staged for exfiltration.


The specific indicators of compromise tied to these campaigns should be available from PaperCut's security advisory and threat intelligence feeds. Deploy them. Run them against logs from the past two to four weeks, not just from today forward.


Beyond patching, the structural questions are worth asking:


  • Does the PaperCut server have internet exposure that isn't necessary?
  • Is it segmented from the rest of the network, or can a compromised print server reach domain controllers and file shares directly?
  • Are PaperCut admin credentials unique and not reused elsewhere?
  • Does the server have monitoring that would catch lateral movement originating from it?

  • For most deployments, the honest answer to several of those questions is uncomfortable.


    ---


    ## HackWire Analysis


    The PaperCut story is, at this point, a case study in how the security industry fails to learn from its own incidents.


    The 2023 exploitation of CVE-2023-27350 was not subtle. It was loud, multi-actor, widely covered, and landed on the CISA KEV list. Every organization running PaperCut should have walked away from that episode with a clearer picture of their exposure and a faster patching pipeline. Many clearly didn't.


    What's striking about this new wave is the zero-day component. Prior PaperCut exploits moved fast after patch publication — the 2023 attacks began within 48 hours of the CVE dropping. This time, attackers had working exploits *before* the fix existed. That requires either independent research into PaperCut's codebase, or access to vulnerability information through channels that predate public disclosure. Neither scenario describes a low-resourced opportunist.


    The data theft framing is worth scrutinizing. Print management servers are not typically thought of as treasure troves, but consider what actually moves through them: legal documents, HR files, financial reports, medical records in clinical settings, contracts. The server does not store the content permanently, but depending on configuration, it may log document metadata, hold print jobs in queues, and cache authentication tokens. Combined with Active Directory integration, a compromised PaperCut server can be a remarkably effective reconnaissance platform.


    The broader pattern here is "shadow infrastructure" — software that handles real sensitive workflows but doesn't live on the security team's mental model of critical assets. HVAC controllers, badge readers, print servers, conference room systems: they all have network access, they all have software vulnerabilities, and they are all monitored less rigorously than the systems security teams traditionally prioritize. Attackers figured this out years ago. Defenders are still catching up.


    If your organization runs PaperCut: patch now, hunt for compromise going back a month, and treat the print server like you treat a domain controller. That last part is the actual fix.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)