PaperCut

PaperCut

Print management software for usage control

Overview

PaperCut provides print management software that helps organizations reduce waste and costs by giving visibility and control over who prints what and how much. It works by tracking and managing print, copy, and scan activities across printers and devices, applying rules, quotas, and secure release to enforce responsible printing. It differentiates itself through easy installation and broad compatibility across printers, devices, and operating systems, plus a strong global support network and long-term relationships with customers, resellers, and employees. The company’s goal is to cut paper use and expenses by guiding users toward more efficient printing habits, backed by a large user base of over 125 million across 195 countries and 85,000+ organizations.

About PaperCut

Simplify's Rating
Why PaperCut is rated
C
Rated B on Competitive Edge
Rated C on Growth Potential
Rated D+ on Differentiation

Industries

Enterprise Software

Education

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Melbourne, Australia

Founded

1998

Get referred to PaperCut

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • PaperCut shipped three emergency patch releases within days, showing fast incident response.
  • Security firms Huntress and watchTowr publicly collaborated, strengthening customer confidence in remediation.
  • Release 3 restored broken SAML and SQL Server drivers, reducing customer friction during upgrades.

What critics are saying

  • CVE-2026-81578 and CVE-2026-82078 enabled unauthenticated RCE; CISA added them August 31.
  • Emergency Patch Release 3 shipped September 4 after Release 2 bypasses, signaling unstable defenses.
  • Version 23 and earlier have no patch; exposed servers risk breach and replacement pressure by Q4 2026.

What makes PaperCut unique

  • PaperCut runs print management for 100 million users across 70,000 organizations.
  • It embeds deeply inside schools, hospitals, and offices, controlling printers and card databases.
  • Cross-platform support across Windows, Linux, and macOS makes replacement operationally painful.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Parental Leave

Hybrid Work Options

Company News

IT Security News
Sep 1st, 2026
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog.

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. 2026-09-01 11:09 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, [...] Read the original article: U.S. U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This... Security Products & Services July 28, 2025 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains... April 21, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its Known... August 31, 2026 In "Cyber Security News"

News4Hackers
Aug 31st, 2026
Exploited PaperCut vulnerabilities: new details and security flaws.

Exploited PaperCut vulnerabilities: new details and security flaws. Post Views: 15 PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems. Overview of the vulnerabilities. PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems. The flaws allow unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code remotely on affected systems. The vendor released a security advisory on August 27 and deployed the first emergency patch the following day for PaperCut NG/MF versions 25 and 26. A second update was released later that same day to address additional risks, including for version 24. Key vulnerabilities identified. CVE-2026-81578. One, tracked as CVE-2026-81578, is a high-severity authentication bypass that enables remote, unauthenticated users to alter specific system configurations. CVE-2026-82078. The second, CVE-2026-82078, involves unsafe dynamic class loading within database connection utilities. The advisory explained that compromising system configuration parameters could allow execution of arbitrary Java bytecode from the application classpath within the PaperCut server's security context. Security implications and response. Indicators of compromise (IoCs) related to the vulnerabilities have been published. Initial reports suggested a single flaw was being exploited, but subsequent analysis by PaperCut and security firms Huntress and WatchTowr confirmed two distinct zero-day vulnerabilities. WatchTowr identified multiple methods to bypass the initial patch and an additional authentication flaw, prompting the second update. Huntress confirmed attacks on at least two clients, with the first exploitation attempts detected on August 26. The firm reported that the activity centered on system reconnaissance, without evidence of secondary malware or further command-and-control interactions. Current status and recommendations. The identity of the attackers and their objectives remain unknown. However, prior incidents involving PaperCut vulnerabilities highlight the risks, as CISA's Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been linked to ransomware campaigns. ShadowServer Foundation data indicates approximately 1,000 PaperCut installations are accessible online, with the majority located in North America and Europe. The company continues to refine its advisory, emphasizing the need for immediate patching and monitoring for signs of compromise. Security teams are urged to review the provided IoCs and implement mitigations to prevent exploitation.

Bank Info Security
Aug 31st, 2026
Attackers actively exploit flaws in PaperCut NG/MF.

Attackers actively exploit flaws in PaperCut NG/MF. Vendor Issues Second Set of Emergency Patches for Printer Management Software Mathew J. Schwartz (euroinfosec) - August 31, 2026 Widely used print management software vendor PaperCut published two emergency patches as it battles attackers actively exploiting zero-day vulnerabilities in its tools. "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing," the company said in an "urgent security advisory" to customers updated on Monday. The Australian company counts 100 million end users of its software, which is designed to facilitate self-management of printers and multi-function devices, including managing and tracking print queues. The company said the software is used for everything from large enterprise and university environments that may number over 100,000 users to smaller organizations that may facilitate printing for fewer than 50 users on just a handful of printers. "The vulnerabilities allow an unauthenticated attacker to bypass authentication and gain remote-code execution on affected instances. Patches are available, but in-the-wild exploitation is already happening," said cybersecurity firm watchTowr in a Friday LinkedIn post. The vulnerabilities appear to affect all versions of PaperCut NG and MF Application Server. PaperCut on Thursday issued emergency patches for versions 25 and 26, followed Friday by an updated set of patches that also extended coverage to version 24, first released in October 2024. The company released indicators of compromise resulting from in-the-wild attacks that organizations can use to hunt for signs that they've been breached. Cybersecurity firm Huntress on Friday said that nearly half of the roughly 2,500 installations of PaperCut that it tracks were running version 23 - released in October 2023 - or older, for which no patches are available. PaperCut told customers it recommends they upgrade their software. Additional mitigation advice from PaperCut is that any organization that makes any version of the software accessible using the public internet should "immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses)," as well as "use firewall rules, network access controls or equivalent measures to ensure the PaperCut server's web interfaces cannot be reached from untrusted internet addresses." The company's patches address two flaws in the software: CVE-2026-82078, an unsafe dynamic class loading in database connector with a critical CVSS score of 9.4, and CVE-2026-81578, an improper access control vulnerability which exists in the software's web management interface with a high CVSS score of 8.8. After shipping a first batch of patches Thursday, the company on Friday released "Emergency Patch Release 2," which it has advised all customers to install, even if they already installed the first patch. The company said the second patch release "includes additional hardening beyond the original emergency patch," gleaned in part thanks to efforts by researchers at Huntress and watchTowr, and it would help to better protect customers who couldn't mitigate the vulnerabilities by not making their PaperCut software public facing. WatchTowr said that after PaperCut first disclosed the flaws Thursday, it was able to reproduce the vulnerabilities as well as find "multiple patch bypasses," including "an additional authentication bypass vulnerability," all of which it's shared with PaperCut. Huntress said it's also created a working proof-of-concept exploit based on the vulnerabilities, and found at least two of its customers have been targeted with exploits for the flaws, one of them on Wednesday. "Post-exploitation activity included base64-encoded commands executed on the targeted server that decoded to commands whoami and ver that aimed to identify the victim's user account and operating system," it said. These aren't the first serious flaws to be found in PaperCut's printer management software. The catalog of known exploited vulnerabilities maintained by the U.S. Cybersecurity and Infrastructure Security Agency features multiple PaperCut NG/MF vulnerabilities, including CVE-2023-27350, an improper access control vulnerability added in 2023 when it was being targeted by ransomware-wielding attackers, as well as CVE-2023-2533, a cross-site request forgery vulnerability added in 2025. On April 20, CISA also added to its KEV catalog CVE-2023-27351, an improper authentication vulnerability in PaperCut NG/MF. The agency warned at the time that the flaw was already being actively exploited by ransomware-wielding attackers.

Falcon Internet
Aug 29th, 2026
PaperCut zero-day under active attack: two emergency patches in 48 hours.

PaperCut zero-day under active attack: two emergency patches in 48 hours. If your organization runs PaperCut NG or PaperCut MF - and with 100 million users at over 70,000 organizations worldwide, there's a real chance it does - stop what you're doing and check your patch level. On August 27, 2026, PaperCut published an urgent security advisory confirming active exploitation of two previously unknown vulnerabilities in its print management software. Emergency patches followed, and then a second round of emergency patches the very next day after researchers identified bypasses in the first fix. The window between disclosure and exploitation was essentially zero: attackers were already inside customer environments when the advisory dropped. What PaperCut is and why this matters. PaperCut NG and PaperCut MF are among the most widely deployed print management platforms in the world, handling print tracking, cost control, and device management across Windows, Linux, and macOS environments. The software is especially prevalent in education, healthcare, and small-to-midsize businesses - exactly the organizations that tend to have fewer people watching their logs at 2 a.m. when an attacker runs whoami on a production server. According to the vendor, 41 percent of its customer base is small businesses. These aren't Fortune 500 shops with a SOC team; they're the kind of organizations whose print server runs quietly in a back office and never makes the vulnerability-management queue. The attack chain: two flaws, zero credentials. Two CVEs are being chained together to produce unauthenticated remote code execution: * CVE-2026-81578 (CVSS 8.8 - High): An improper access control vulnerability in PaperCut's web management interface. The flaw arises from a page-rendering mismatch: PaperCut's authorization check trusts the rendered page but fails to verify the permissions required by the back-end component actually executing the action. An unauthenticated attacker can send a specially crafted request that routes through the authorization check without tripping it, then triggers administrative functions - including configuration writes - on the server. * CVE-2026-82078 (CVSS 9.4 - Critical): An unsafe dynamic class-loading vulnerability in PaperCut's database connection utilities. The application instantiates database driver classes based on a configurable driver name, without validating those names against any allowlist. Once an attacker has used CVE-2026-81578 to write a malicious driver reference into a configuration file, CVE-2026-82078 loads and executes arbitrary Java bytecode - giving the attacker arbitrary code execution under the PaperCut application server's service account, which in default Windows installations runs as SYSTEM. Huntress researchers confirmed the chain works in practice, developing a proof-of-concept exploit that spawned charmap.exe processes running as SYSTEM under the PaperCut server process. The attack is fully pre-authentication. What attackers are actually doing. Huntress observed confirmed exploitation in two customer environments. Post-exploitation activity was consistent with initial reconnaissance: hex-encoded Java .class files (named Udydn.class and Moo97.class) were deployed to the server, executing system discovery commands including whoami & ver and tasklist, writing output to files, then deleting logs and themselves to cover their tracks. The cleanup behavior suggests deliberate operational security on the attacker's part - this wasn't opportunistic noise. A reliable forensic indicator is a suspicious log entry containing DB URL: jdbc:derby:memory:pwn alongside irregular Apache Derby database boot messages. If you're searching logs and see that string, treat it as confirmed compromise and begin incident response immediately. The patch situation: read this carefully. PaperCut released its first emergency patch on August 27-28 for NG and MF versions 25 and 26, with version 24 patches following shortly after. If you applied that first patch and stopped there, you may not be fully protected. On August 28, PaperCut released Emergency Patch Release 2 after researchers at watchTowr and Huntress identified multiple methods to bypass the initial fix. Release 2 includes additional hardening beyond the original patch, developed collaboratively with both firms. This is the build you need to be running right now. Affected scope: all versions of PaperCut NG and MF prior to August 27, 2026. Patches are available for versions 24, 25, and 26 on Windows, Linux, and macOS. If you are running version 23 or earlier, no patch is available for your release - upgrade to a current supported version immediately. Patched version numbers for PaperCut version 25: 25.0.12.76497 (NG) and 25.0.12.76496 (MF). Confirm your exact build number in the PaperCut admin interface under About before assuming you are protected. What to do right now. * Patch to Emergency Patch Release 2 immediately. Verify the exact build number, not just the version banner. * Take PaperCut off the public internet. The application server should be accessible only from trusted internal networks or via VPN. There is no legitimate reason to expose a print management interface to the open web. * Hunt for the compromise indicator. Search application and server logs for jdbc:derby:memory:pwn and for unexpected Derby database boot events. Also look for unknown .class files dropped to the PaperCut server directory and for charmap.exe spawned from the PaperCut process. * Preserve evidence before patching if you find indicators. Copy server logs, configuration files, and process tree snapshots before applying patches - forensic data is overwritten quickly, and you'll want it for incident response. * Audit service account privileges. If PaperCut runs as SYSTEM or a highly privileged domain account on your Windows systems, consider constraining that account to a dedicated low-privilege service identity as a long-term hardening measure. The pattern worth noting. PaperCut went through an almost identical situation in 2023, when CVE-2023-27350 and CVE-2023-27351 were exploited before many organizations could patch. The lesson then, as now, is that print management servers - quiet infrastructure that nobody thinks about - are exactly what attackers target for initial access. They're typically trusted on the internal network, often run with elevated privileges, and rarely appear on penetration testing scope lists. At Falcon Internet, seeing servers like this exploited is part of why its NOC monitors for anomalous process trees, not just perimeter alerts. Apply Release 2. Check your logs. If you haven't explicitly restricted your PaperCut management interface to an internal-only network segment, do that now, before you do anything else.

Adaptive Perspectives, 7-day Insights
Aug 28th, 2026
PaperCut print servers are under attack, and one patch wasn't enough.

PaperCut print servers are under attack, and one patch wasn't enough. Two chained flaws in PaperCut NG/MF give unauthenticated attackers remote code execution, and they're being exploited now. The first emergency patch was bypassed, so a second shipped Friday. Here's what to do this weekend. Note: This post was written by Claude Fable 5. The following is a synthesis of PaperCut's security bulletin and reporting from major security-news organizations. Print management software is not where most IT teams expect their next emergency to come from, which is exactly why it keeps happening. PaperCut NG/MF - the print-accounting platform that sits in a large share of universities, hospitals, and corporate networks - is under active attack again, and the fix moved twice in two days. If you run it, this is a weekend job, not a Monday one. What's wrong. PaperCut disclosed on August 27 that its security team was investigating confirmed customer incidents. A day later it published CVE identifiers and technical detail for two vulnerabilities that chain together: * CVE-2026-82078 (CVSS 9.4, critical) - an unsafe dynamic class-loading flaw in PaperCut's database connection utilities. The application loads database driver classes by configurable name without checking them against an allowlist, so an attacker who can alter configuration parameters can run arbitrary Java bytecode as the PaperCut server process. * CVE-2026-81578 (CVSS 8.8, high) - an authentication bypass in the web management interface. Under specific conditions, unauthenticated remote requests to administrative functions trigger backend actions before access-validation checks complete - which is precisely how an outsider gets to "alter configuration parameters" for the first bug. Together they hand an unauthenticated attacker remote code execution on the server. The security firm watchTowr, which worked the incident with PaperCut, confirmed that reading of the chain. PaperCut says the advisory applies to all versions of NG and MF, and that the attacks it has seen so far look "limited and targeted." Why it patched twice. PaperCut shipped an initial emergency patch alongside the August 27 disclosure. Then watchTowr's researchers fully reproduced the vulnerabilities, found multiple ways to bypass that first fix, and turned up an additional authentication-bypass flaw. So on Friday, August 28, PaperCut released Emergency Patch Release 2, with hardening developed together with Huntress and watchTowr beyond the original. The company is explicit that Release 2 supersedes the first patch: install it even if you already applied the earlier one. That's the detail most likely to bite a team that patched Thursday, felt covered, and stopped reading. What organizations running PaperCut should do. The bulletin's guidance, in the order PaperCut puts it: * Restrict the web interface right now, patch or not. If your PaperCut Application Server is reachable from the public internet, limit web access to trusted internal IP addresses immediately, using firewall rules or network access controls. PaperCut says to do this even if you have seen no suspicious activity - a print server has no business exposing its admin interface to the open internet, and this closes the attack path while you schedule the rest. * Apply Emergency Patch Release 2. It is available for NG/MF versions 24, 25, and 26 on Windows, Linux, and macOS. Download from the bulletin and follow the standard upgrade procedure; PaperCut publishes SHA-256 checksums for each build, so verify what you download before you run it. * If you're on version 23 or earlier, upgrade. There is no back-patch for those releases - the recommended path is to move to a current, patched version. * Don't forget the other servers. Site Servers and secondary/print servers need the patched version too, not just the primary Application Server. Print Deploy and Mobility Print are not affected and need no update. * Hunt for compromise before you close the book. PaperCut names three indicators: intrusion-detection, endpoint, or network alerts tied to the PaperCut Application Server - especially suspicious activity from the pc-app.exe process; missing, truncated, or deleted server.log files; and either of these lines in server.log: ERROR No suitable driver found for jdbc:no:x ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST PaperCut is careful to say the absence of those indicators does not prove you're clean, and that it will publish validated indicators of compromise as its investigation continues. Treat a patched server as remediated, not as proven-uncompromised - if it was internet-facing and unpatched, assume it may have been reached and investigate accordingly. PaperCut servers were mass-exploited in 2023, when CVE-2023-27350 drew ransomware crews - Cl0p and LockBit among them - that used exposed print servers as an initial foothold into the wider network. That history is the reason a "just a print server" shrug is the wrong instinct here. PaperCut runs with database access and service-level privileges, usually deep inside the network, which makes it a useful pivot point rather than a dead end. It also answers a question many teams will ask: if the server never touches the internet, is this still urgent? The exploitation reported so far targets public-facing servers, so an internal-only install sits outside the path of the indiscriminate scanning that follows disclosure, and the immediate pressure is lower. But the authentication-bypass flaw needs no credentials and is reachable from anywhere on the local network, and a privileged print server is a textbook lateral-movement target - so "not exposed" is one control, not a clean pass. Patch it promptly regardless; applying Release 2 while nobody is probing the server beats doing it mid-incident, and limiting the management interface to trusted internal hosts adds a second layer. Nobody has attributed the current campaign or described what attackers are doing post-compromise; PaperCut is withholding those details while its investigation runs, reasoning that premature specifics could complicate victims' own response. The prudent assumption, given the 2023 pattern and the speed of the patch-bypass work, is that exploitation will broaden now that the CVEs are public and the chain is understood. The window to be ahead of that is this weekend.

Recently Posted Jobs

Sign up to get curated job recommendations

PaperCut is Hiring for 4 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →