PaperCut Zero-Day Flaw: What SMBs Must Do Now

A serious vulnerability in PaperCut — one of the most widely used print management software platforms in the world — is being actively exploited by attackers before a fix was even publicly available. That kind of attack has a name: a zero-day exploit. And for small and medium businesses running PaperCut NG or MF on their networks, this is not a story to scroll past.

What Is the PaperCut Zero-Day and Why Does It Matter?

PaperCut NG and MF are software tools that help businesses manage printing across their organisation — tracking usage, setting permissions, and handling print queues across multiple devices. Thousands of SMBs, schools, and healthcare providers rely on them. That widespread use is exactly what makes this vulnerability attractive to attackers.

The flaw allows a remote attacker — someone with no prior access to your systems — to execute code on a vulnerable server. In plain terms, that means an outsider can potentially take control of a machine running unpatched PaperCut software without needing a password or an invitation. Attackers were already using this weakness in the wild before PaperCut had the chance to issue a public patch, which is what earns it the zero-day label.

For businesses, the consequences of a successful attack like this can include ransomware deployment, data theft, and prolonged network access by threat actors who operate quietly for weeks or months before making their move.

Who Is at Risk and What Should You Check First?

If your business uses PaperCut NG or MF, the first question to answer is whether your installation is internet-facing — meaning accessible from outside your internal network. Print management servers that are exposed to the public internet carry a significantly higher risk in this scenario. However, even internally hosted systems are not entirely safe if an attacker has already gained a foothold elsewhere in your network.

The immediate action is to apply the patches PaperCut has now released. If you have an IT team or a managed service provider, this should be their top priority today. If you manage your own systems, log in to the PaperCut admin panel and check your current version number against the patched versions listed in PaperCut's official security advisory.

Beyond patching, restrict external access to your PaperCut server if it does not need to be reachable from outside your office network. A print management tool rarely needs to be publicly accessible, and limiting that exposure is a straightforward layer of protection.

The Broader Risk: Credential Theft After a Compromise

Here is what often gets overlooked in conversations about vulnerabilities like this one. When attackers gain access to a server through an exploit, their goal is rarely limited to that single machine. They move laterally — meaning they use that entry point to explore the wider network, harvest stored credentials, and gather anything valuable.

Print servers often sit in a privileged position on a corporate network. They may hold authentication data, integration credentials, or access to file shares and databases. Once an attacker has been inside your environment, even briefly, the damage can persist long after you patch the original hole.

This is where Breachrr's monitoring becomes directly relevant. We continuously scan breach databases, infostealer malware dumps, dark web markets, public code repositories, and domain infrastructure for signs that your business data has been exposed. If credentials harvested from a compromised server end up in a dump file being traded on a dark web forum, Breachrr finds it and alerts you — before attackers have the chance to use that access again.

Patching Is Step One, Not the Whole Plan

The PaperCut zero-day is a useful reminder that vulnerability management and breach monitoring are two separate disciplines that work best together. Patching closes the door. Monitoring tells you whether someone already came through it.

For SMBs without a dedicated security team, it can be difficult to know what you don't know. That is exactly the gap Breachrr is built to close. If you want to understand whether your business credentials, domains, or infrastructure data are already circulating in places they shouldn't be, run a free audit at breachrr.com/audit. It takes minutes and gives you a clear picture of your current exposure.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →
PaperCut Zero-Day Flaw: What SMBs Must Do Now · Breachrr · Breachrr