PaperCut Issues an Emergency Patch, Saying Customers Are Already Under Attack

PaperCut released an emergency patch for its PaperCut NG and PaperCut MF print management servers early on Aug. 28, hours after the company said it was investigating active exploitation of a vulnerability in both products.
The company's security bulletin, first published Aug. 27, says its security response team "is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF" and that the company is "aware of confirmed customer incidents."
According to the bulletin's change log, the patch was published at 2:10 a.m. AEST on Aug. 28 and covers versions 25 and 26 of both products. PaperCut says it did not follow its normal procedure. Asked in its own FAQ whether this is an official release, the company answers: "No. We have not gone through our usual release process." Builds for version 24 are "still in progress," per the same FAQ.
The advisory applies to all versions of PaperCut NG and PaperCut MF, the company says. It tells administrators whose servers are reachable from the public internet to restrict web access to trusted addresses immediately, and to do so "even if you have not observed suspicious activity."
The bulletin carries no CVE number, the standard public identifier given to a security flaw, and no severity score or technical description. PaperCut says it will update the page "as verified information becomes available, including indicators of compromise and remediation guidance," and that the absence of the preliminary indicators it lists is not confirmation that a system has not been affected.
The company says information supplied by a university customer's security team and its incident response team let PaperCut reproduce the vulnerability in its own code.
PaperCut also says the patched builds change one feature. Sites that look up card or ID numbers from an external database can no longer use certain database query commands in those lookups, and the company tells those customers to read its FAQ before installing.
