PaperCut Just Patched the Same Zero-Day Twice — Here's Why That Should Scare You
Here's a sentence that should make any IT person put down their coffee: the emergency patch has its own emergency patch.
That's where PaperCut landed this week. PaperCut NG and MF — print management software that runs in thousands of offices — had a zero-day under active exploitation. They released an emergency patch. Then researchers found new ways to exploit the same flaws, and a second emergency patch had to go out almost immediately after. BleepingComputer confirmed active exploitation across both cycles, and Huntress flagged at least two verified compromises in the MSP community before the dust settled.
If you run PaperCut in your environment and you haven't patched to Release 2, you are currently exposed. That's not a maybe.
But the bigger issue isn't the patch — it's the cycle.
What happened with PaperCut this week isn't actually rare. It's a pattern. A critical vulnerability gets disclosed. A patch goes out fast—because speed feels like safety. Then the researchers who found the original flaw, or other teams who started digging, find adjacent attack paths the first patch didn't close. And now you're in round two of an emergency, except this time the bad actors already know where to look.
This matters for small businesses in Manitoba for a specific reason: most of you don't have a dedicated security team checking vendor bulletins on a Tuesday afternoon. You have whoever manages your IT — maybe that's an in-house person, maybe that's me — and that person has about twelve other things happening. Patch fatigue is real. "We just patched that" is a sentence that can get a network compromised.
The Huntress thread on Reddit's r/msp had MSPs describing active exploitation happening before some clients even finished deploying the first patch. That's not a comfortable timeline.
What actually happens when print management software gets hit
Print servers aren't glamorous. They sit in the corner of the server room or in a VM, and nobody thinks about them until the Xerox stops working. But PaperCut runs with elevated privileges on most deployments — it has to, to manage print queues and user authentication across the network. That means a successful exploit doesn't just get you print logs. It can be a pivot point into the broader network.
ShinyHunters pulled 86 GB out of Manchester Airports Group this week. McKesson disclosed a breach the same week involving third-party application access. These aren't all print server stories — but they're all the same story: attackers are patient, they know which software sits with high privileges and low attention, and they wait for the window.
PaperCut just opened a window. Twice.
Here's what you actually do this week
If you're a small-business owner and you have a print management tool on your network — PaperCut or otherwise — here's your short list:
Ask your IT person which version you're running. Not which version you updated to last month. Which version is running right now, confirmed.
Make sure they know about Release 2, not just the first patch. The first patch was not sufficient. PaperCut's own advisory makes this clear.
If you don't have an IT person actively watching vendor advisories, that's a gap worth talking about. Not a sales pitch — just a reality. These advisories move fast, and they're written in a language most business owners don't have time to parse.
Check your exposure. Is your PaperCut instance internet-facing? Does it need to be? Most print management software does not need to be reachable from outside your network, and if it is, that's worth closing regardless of patch status.
The patch is necessary. The patch alone is not enough. The question underneath all of this is whether anyone in your corner of the building is watching when these things happen — not after the fact, but in the window that matters.
If you're running PaperCut and want a second set of eyes on your patch status this week, reply or message me. No charge to look.
Recommended Comments