PaperCut’s Web Console Opened the Copier Fleet

PaperCut Software says an unspecified PaperCut NG/MF vulnerability is under active attack, with confirmed customer incidents and a warning that the Application Server should not be reachable from the public internet. PaperCut NG manages printing; PaperCut MF extends that control into multifunction copiers and their touchscreens. The risk is not just to the server itself. PaperCut’s Application Server is the control point for the print-management plane, so if an attacker reaches it, they can drive copier functions and potentially pivot into the embedded interfaces on the devices it manages. That makes exposed PaperCut servers a boundary problem, not a routine server patch issue. For organizations that let the web interface face the internet, the exposure can extend from a single management host to the physical office devices hanging off it, and the vendor says it is still investigating what specific flaw is being used.

Part of the PlainSec briefing for 2026-08-27

Editions

Sources