Somewhere in your environment there’s a print management server that hasn’t been restarted since the last time IT rotated its password, which was also the last time anyone logged into it on purpose. This week, if that server is running PaperCut NG or MF, it’s the reason your weekend is ruined. PaperCut confirmed a zero-day being actively exploited across every supported version of both products and rushed out an emergency patch, which is corporate-speak for “we found out the same way you did: because someone already got in.” If this story feels familiar, that’s because it is. This is a cybersecurity industry running the same play it ran in 2023, when a different PaperCut flaw became a favorite on-ramp for ransomware crews. Software doesn’t have to be exciting to be dangerous. It just has to be everywhere and unwatched.

PaperCut print management software interface representing the exploited zero-day
PaperCut’s emergency patch covers every supported NG and MF version after confirmed exploitation in the wild.

The Zero-Day Nobody Wanted, But Should Have Expected

PaperCut says it’s aware of confirmed customer incidents and is treating the situation with “highest priority,” which is the kind of sentence that means the incident response team hasn’t slept. No CVE identifier has been assigned yet, but the company is telling every NG and MF customer to patch now and apply mitigations in the meantime. That’s not caution, that’s an admission the exploit is already loose and working. For a piece of software that most companies think of as plumbing, that’s a big deal. Print servers routinely run with elevated local or domain privileges because someone, at some point, needed them to talk to every printer on the floor without a support ticket every time a driver update rolled out. Attackers know this. They’ve known it since the last time this exact category of software got popped.

Print Management Is the Softest Target You Forgot About

Nobody puts print management on their threat model. It doesn’t hold customer data, it doesn’t process payments, and it’s rarely the star of a tabletop exercise. That’s exactly why it keeps showing up in breach reports. A server that’s invisible to your risk conversations is also invisible to your monitoring, and invisible is precisely where attackers want to operate. The 2023 PaperCut vulnerability wasn’t a one-off embarrassment; it became a documented pathway into networks for ransomware affiliates precisely because these servers sit quietly with more access than they need and less scrutiny than a laptop. This new zero-day follows the same script: high-privilege software, low-visibility monitoring, and an attacker who found the gap before the defenders did.

The uncomfortable truth is that this pattern isn’t unique to PaperCut. Any product that’s been bolted onto your network for a decade, that “just works,” that nobody wants to touch because breaking it means printers stop functioning company-wide, is a candidate for the same treatment. Legacy trust plus quiet privilege equals a long-term liability that only gets noticed after someone else finds it first.

What Actually Buys You Time While the Vendor Catches Up

Waiting on a patch is not a strategy. Neither is hoping your firewall rules from three years ago still make sense. If you run PaperCut, or honestly any management console with admin-level reach, here’s what should already be in place and what to check today:

  • Confirm the emergency patch is applied to every NG and MF instance, not just the one someone remembers exists.
  • Restrict management interfaces to internal networks only; nothing administrative should be reachable directly from the internet.
  • Segment print infrastructure from domain controllers and file shares so a compromised print server can’t casually walk sideways into the crown jewels.
  • Turn on logging for authentication attempts against the admin console and actually route those logs somewhere a human or a detection rule will see them.
  • Use dynamic IP banning at the edge, something like IPBan Pro, to automatically shut down brute-force and credential-stuffing attempts against exposed login pages before they turn into a foothold.
  • Rotate service account credentials tied to the print server on a schedule, not just when someone remembers to.

None of this is exotic. It’s security hardening 101, applied to the boring server everyone forgot to include in the plan. Defense in depth doesn’t mean stacking five different tools on your web app while the print server runs wide open with a decade-old password. It means treating every privileged system, glamorous or not, as a real part of your attack surface.

The Boring Infrastructure Problem Isn’t Going Away

There’s a reason threat detection vendors keep talking about exposure management and unified visibility this year; the industry is slowly admitting that most breaches start in the parts of the network nobody was watching. Tenable’s own CSO wrote this week about tearing down a “spaghetti chart” of fifty-plus disconnected tools to get a single view of risk across the business. That’s the right instinct, but it only works if boring, ancient, high-privilege systems like print servers actually make it onto the chart in the first place. Meanwhile Android 17 is out here hardening DNS queries against network snooping, and Cloudflare just shaved 100 terabytes of memory off its own DNS cache through careful engineering. The rest of the industry is polishing edge cases while a print server with domain-level access sits exploitable in a closet somewhere. Priorities, as always, are a choice.

Incident response teams don’t get to choose which system the attacker picks. They only get to choose how fast they notice and how far the blast radius spreads once someone does. A patched, segmented, logged print server is boring. An unpatched one making headlines next to the word “ransomware” is not the kind of exciting anyone wants.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.