🔒 Client Login Order Supplies Submit Meter Read Request Service Get a Quote

PaperCut Security Vulnerability: 5 Essential Steps to Protect Your Business Now

PaperCut security

If your office uses PaperCut NG or PaperCut MF for print management, you need to act on this today. An urgent PaperCut security vulnerability has been confirmed — one that affects all versions of the software. If your PaperCut web interface is accessible from outside your internal network, you’re exposed right now.

The good news: patches are out for versions 25 and 26. The bad news: if you haven’t applied them yet, your print server may be reachable by anyone on the internet — and there are confirmed indicators of active exploitation. Here’s what’s happening and what to do about it.

What Is the PaperCut Security Vulnerability?

This PaperCut security issue affects both PaperCut NG and PaperCut MF — the two most widely deployed print management platforms in offices, schools, and government agencies. PaperCut’s own security team flagged it as urgent and sent alerts directly to all registered security notification subscribers.

The core problem: if your PaperCut server’s web interface is reachable from untrusted internet addresses — meaning someone outside your office network can load that login page — your server is at risk. PaperCut has confirmed patches for versions 25 and 26 on Windows, Mac, and Linux. Older versions remain vulnerable without a patch. There are known indicators of compromise, which means attackers are actively scanning for exposed systems.

PaperCut Security Risk: Who’s Actually Exposed?

Any business running PaperCut NG or MF with its web interface reachable from the internet is at risk. That typically includes:

  • Remote administration setups where IT staff access the PaperCut admin panel from outside the office without a VPN
  • Offices using PaperCut’s web-based user portal without network access controls blocking public internet access
  • Multi-site operations where print servers are reachable across public internet connections

If your PaperCut setup is only accessible from inside the building or through a secure VPN, your immediate risk is lower — but you should still apply the patch. Defense in depth matters when confirmed active exploitation is in play.

5 Steps to Address the PaperCut Security Issue Right Now

PaperCut’s guidance is clear. Two parallel tracks — do both if you can:

1. Block the exposure immediately. Use firewall rules or network access controls to ensure your PaperCut server’s web interfaces are unreachable from untrusted internet addresses. This is your fastest mitigation if patching requires scheduling.

2. Upgrade to the patched version. If you’re running PaperCut NG or MF version 25 or 26, upgrade to the latest patched release now. Patches cover Windows, Mac, and Linux. Versions older than 25 don’t have a patch yet — the firewall block is your mitigation until one is released.

3. Check for indicators of compromise. PaperCut’s security advisory includes guidance on what to look for. If your server was exposed before this alert, review your logs against those indicators.

4. Subscribe to PaperCut security notifications. You shouldn’t hear about a PaperCut security advisory like this secondhand. Subscribe at papercut.com/contact/security so future alerts reach you directly.

5. Test your exposure now. Pull up a browser on your phone on LTE (not your office WiFi) and try loading your PaperCut URL. If the login page loads, you’re exposed. If that test makes you nervous, call your IT team or managed IT provider today.

Why Print Management Software Is a High-Value Target

PaperCut security matters beyond “it’s just print software.” Print management sits at the intersection of your network, your users, and your documents. PaperCut controls who can print, logs everything that prints, handles user authentication, and often connects directly to Active Directory or LDAP. Compromise the print server and you potentially get credential visibility and a network foothold — which is exactly why attackers go after it.

The confirmed active indicators of compromise make this a drop-everything situation, not a “schedule it for next month” item. The longer an exposed server sits unpatched, the higher the odds of an incident.

What This Means for Tallahassee Businesses

ABS manages Canon, Kyocera, Ricoh, and Toshiba fleets for businesses across Tallahassee, Thomasville, and North Florida and South Georgia. If your copier fleet runs PaperCut and you’re not certain whether you’re patched or whether your web interface is internet-facing, contact us. We can review your setup and help you get current quickly.

If you’re already on ABS’s managed IT services, your team should be all over this. If you’re managing print independently, don’t wait on this PaperCut security issue — the confirmed active exploitation changes the urgency calculus. Call (850) 222-2308 or reach out here and we’ll take a look.

Frequently Asked Questions

Q: Our PaperCut server is behind our office firewall and not internet-facing. Do we still need to do anything?
A: Your immediate risk is lower, but yes — upgrade to the latest patched version anyway. PaperCut security best practice doesn’t stop at “not exposed today.” Internal threats, VPN misconfigurations, and future changes can shift that exposure.

Q: We’re on an older version of PaperCut. When will a patch be available for it?
A: Patches are currently available for PaperCut NG and MF versions 25 and 26. For older versions, block the web interface at the firewall and monitor PaperCut’s security bulletin page for updates on older-version patches.

Q: How do we know if our system has already been compromised?
A: PaperCut’s security advisory includes specific indicators of compromise and investigation steps. Review your server logs against those indicators. If you’re not sure how, loop in a managed IT provider — this isn’t the time to guess.

Related Resources from ABS

Scroll to Top