Logo

PaperCut Zero-Day: What Small Businesses Must Do Now

If your business prints anything – invoices, delivery dockets, staff rosters, client paperwork – there’s a good chance you’re running print management software behind the scenes, and PaperCut is one of the most widely used products in this space, including across regional Victorian businesses, schools and local government offices. That’s why the news that PaperCut has just confirmed a zero-day vulnerability being actively exploited in the wild is worth every small business owner’s attention, even if you’ve never heard of the software by name.

What actually happened

PaperCut NG and PaperCut MF – the two main versions of the software used to manage and track printing across a network – have a security flaw that affects every supported release. According to PaperCut, attackers are already exploiting it in real incidents, not just in theoretical research. The company has rushed out an emergency patch for versions 25 and 26, describing the situation as its highest priority. Separately, researchers have also detailed how two related PaperCut flaws can be chained together to let an attacker execute code without ever needing a username or password, effectively handing them remote control of the server hosting the software.

In plain terms: if a business is running an unpatched, internet-exposed PaperCut server, an attacker could potentially take control of that machine without any login credentials at all. From there, depending on how the network is set up, they could pivot to other systems, steal data, or deploy ransomware.

Why this matters even if you’re “just a small business”

It’s tempting to assume that vulnerabilities like this are an “enterprise IT” problem – something for hospitals, universities or big corporates to worry about. In reality, PaperCut is popular precisely because it’s affordable and easy to deploy, which means it’s sitting quietly on the network of accounting firms, medical practices, real estate agencies, manufacturers and local councils right across regional Victoria. Many of these businesses set the software up once, years ago, and haven’t thought about it since – which is exactly the kind of target attackers are hoping to find.

Small businesses are often more attractive to opportunistic attackers than people assume, not less. Automated scanning tools don’t care how many staff you employ – they simply look for servers running vulnerable software and exposed to the internet, then attack indiscriminately. A regional business with a forgotten print server can be just as exploitable as a capital-city corporation.

Who’s most at risk

  • Businesses running any version of PaperCut NG or MF that hasn’t been patched with the emergency fix
  • Businesses that allow remote access to their PaperCut admin console from outside the office network
  • Organisations where IT maintenance has been ad-hoc, or where “someone set it up once” and it hasn’t been reviewed since
  • Businesses that share infrastructure – for example, a single server also running other line-of-business software – since a compromise of the print server can spread further

What to do right now

1. Confirm whether you actually run PaperCut

If you’re not sure, ask whoever manages your IT – internally or externally – whether PaperCut NG or MF is part of your environment. Many businesses use it without realising it’s a distinct piece of software sitting behind their printers and copiers.

2. Patch immediately

If you do run PaperCut, the single most important action is applying the emergency patch PaperCut has released for the affected versions. Given that this is being actively exploited – not just theoretically vulnerable – this isn’t a “get to it next month” task. It should be treated as urgent, the same way you’d treat a burst pipe.

3. Check what’s exposed to the internet

PaperCut’s admin console and web interface should never be directly accessible from the public internet unless there is a very specific, well-secured reason for it. If your print server can be reached from outside your office network, that’s a separate risk worth closing off regardless of this particular vulnerability.

4. Review access logs for anything unusual

If your provider has the ability to check server or application logs, it’s worth having them look for unfamiliar logins, unexpected admin activity, or newly created accounts around the time this vulnerability became public. Early detection is far cheaper than cleaning up after a full compromise.

5. Make sure backups are current and separate

This kind of vulnerability is exactly the sort that ransomware groups love to exploit – unauthenticated code execution gives them a foothold to spread further into a network. A backup that’s disconnected from your main network, and tested recently, is your safety net if the worst happens.

The bigger lesson: patching can’t be an afterthought

As reported by The Hacker News, this PaperCut issue is one of several critical vulnerabilities disclosed in a single week affecting widely used business software. That’s not unusual – it’s the normal pace of the threat landscape now. The businesses that get hurt aren’t usually the ones targeted specifically; they’re the ones that didn’t apply a patch that had already been made available.

For a small business without a dedicated IT department, the practical solution isn’t to personally track every vulnerability disclosure – it’s to have a system in place that ensures software gets patched promptly as a matter of routine, and that internet-facing systems are regularly reviewed for unnecessary exposure. A print management server might seem like a low-priority piece of the puzzle, but as this incident shows, attackers don’t discriminate based on how “important” a system seems – they discriminate based on how easy it is to break into.

Key takeaways

  • PaperCut NG and MF have a zero-day vulnerability being actively exploited right now
  • An emergency patch is available and should be applied immediately
  • Admin interfaces should never be openly accessible from the internet
  • Check logs for signs of compromise if your system was unpatched and exposed
  • Use this as a prompt to review your overall patching routine, not just this one product

Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions