PaperCut Zero-Day: What Pittsburgh SMBs Need to Patch Now

What happened
According to bleepingcomputer.com, PaperCut has issued a warning that a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software is being actively exploited in zero-day attacks. That means attackers already found and are using the flaw before a patch was widely available or applied, which is about as urgent as security advisories get.
The article doesn't specify every technical detail of the exploit chain, and PaperCut's own advisory is the authoritative source for affected version numbers, CVE identifiers, and patched builds. If you run PaperCut anywhere in your environment, the first move isn't to guess at severity, it's to go pull PaperCut's official advisory and your current build number and compare them directly.

Why this matters for Pittsburgh businesses
PaperCut is one of the most common print management platforms sitting behind law firms, CPA offices, healthcare practices, and manufacturers across the region, precisely because it's affordable, easy to deploy, and does its job quietly in the background. That's also exactly the profile of software that gets forgotten during patch cycles: it's not email, it's not the file server, so it slides down the priority list. Attackers know this.
For a 10-200 employee firm, PaperCut typically runs with elevated privileges to talk to printers, print servers, and sometimes Active Directory for user authentication. A compromised print server is rarely the end goal, it's a foothold. From there, an attacker pivots toward file shares, client records, or protected health and financial data. If you're a healthcare practice with HIPAA obligations, a CPA or financial services firm handling client financial data, a law firm holding privileged documents, or a defense contractor tracking CUI under CMMC, an unpatched print server isn't a minor IT housekeeping item, it's a potential breach-notification event and a compliance finding waiting to happen.
The zero-day nature of this also matters regionally: smaller Pittsburgh-area IT teams and single-person IT departments often don't have vulnerability scanning or asset inventories that flag third-party print software the same way they flag operating systems or firewalls. That visibility gap is exactly where this kind of exploit thrives.
What to do about it this week
- Identify every instance of PaperCut NG or MF in your environment. Don't rely on memory, check your RMM/asset inventory, server list, and any branch office or remote site that might run its own print server.
- Compare your installed version against PaperCut's official advisory to confirm whether you're on an affected build, and note the specific patched version you need to move to.
- Apply the vendor patch as an emergency change, not on your normal monthly patch cycle. Given active exploitation, treat this like a same-week or same-day priority.
- Check external exposure. Confirm whether your PaperCut admin console or print server is reachable from the internet in any way (direct port forwarding, exposed remote access, etc.) and lock that down regardless of patch status.
- Review recent logs on affected servers for unusual admin actions, new user accounts, or unexpected script execution, since zero-day exploitation windows mean some environments may have been touched before a patch was even available.
- Confirm your EDR/MDR coverage extends to print servers, not just workstations and domain controllers. Print servers are frequently under-monitored endpoints.
- Document the remediation (what was found, what was patched, when) for your compliance file, whether that's HIPAA, SOC 2, CMMC, or FTC Safeguards Rule evidence of timely vulnerability management.
If you're not sure how to answer item one confidently, that's the real finding here, not the vulnerability itself.
How we help
This is exactly the kind of gap that structured managed IT and cybersecurity programs are built to catch before it becomes a headline: current asset inventories, patch management with emergency-change procedures for active exploits, and EDR/MDR coverage that extends past the obvious endpoints to servers like these. If your compliance obligations touch HIPAA, SOC 2, or CMMC, we can also help you turn this remediation into documented evidence rather than a scramble. If you're not confident your PaperCut instances (or any third-party software, for that matter) are being tracked and patched on a real schedule, let's talk this week: call 724.888.7007 or reach out through the contact form.
Related reading

CISA Orders Urgent Zimbra Patch: What Pittsburgh SMBs Should Do
CISA ordered urgent patching of an actively exploited Zimbra flaw. Here is what Pittsburgh SMBs running Zimbra should do this week to stay ahead of attackers.

Defender's Own Boot Driver Can Be Turned Against You
Check Point Research shows Microsoft Defender's BTR.sys driver can be abused to wipe security tools at boot. What Pittsburgh SMBs should do this week.

Max-Severity Entra ID Flaw Exploited: What Pittsburgh SMBs Should Do
Microsoft patched a max-severity Entra ID flaw exploited in attacks. Here is what Pittsburgh SMBs on Microsoft 365 should check this week, step by step.