PaperCut

PaperCut

Print management software for usage control

Overview

PaperCut provides print management software that helps organizations reduce waste and costs by giving visibility and control over who prints what and how much. It works by tracking and managing print, copy, and scan activities across printers and devices, applying rules, quotas, and secure release to enforce responsible printing. It differentiates itself through easy installation and broad compatibility across printers, devices, and operating systems, plus a strong global support network and long-term relationships with customers, resellers, and employees. The company’s goal is to cut paper use and expenses by guiding users toward more efficient printing habits, backed by a large user base of over 125 million across 195 countries and 85,000+ organizations.

About PaperCut

Simplify's Rating
Why PaperCut is rated
C
Rated B on Competitive Edge
Rated C on Growth Potential
Rated D+ on Differentiation

Industries

Enterprise Software

Education

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Melbourne, Australia

Founded

1998

Get referred to PaperCut

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • PaperCut shipped maintenance releases on September 11, 2026, replacing emergency patches with QA-tested builds.
  • The company published hardening, indicators, and network-isolation guidance within days of exploitation.
  • CISA's September 14 deadline forced rapid remediation across federal customers and downstream vendors.

What critics are saying

  • CVE-2026-81578 and CVE-2026-82078 enabled pre-auth RCE; CISA listed both August 31, 2026.
  • Attackers breached at least 395 organizations in 48 countries, concentrated in U.S. education.
  • Version 23 and earlier remain unpatched; internet-exposed servers face immediate compromise and ransomware pivoting.

What makes PaperCut unique

  • PaperCut runs print management across schools, hospitals, and offices, embedded in trusted networks.
  • Its software controls printers, queues, and usage accounting for 100 million users.
  • Version 26.0.5, 25.0.13, and 24.1.10 unified emergency fixes into tested maintenance releases.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Parental Leave

Hybrid Work Options

Company News

The Hacker News
Sep 11th, 2026
PaperCut replaces emergency patches with fixes for two actively exploited flaws.

PaperCut replaces emergency patches with fixes for two actively exploited flaws. Ravie LakshmananSep 11, 2026 Vulnerability / Cyber Attack PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said. "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process." It's worth noting that the release supersedes the emergency patches that were shipped to address two security flaws as well as two regressions, along with various hardening and mitigation against potential attack chains. The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances. In one case highlighted by GreyNoise and Blackpoint Cyber, a suspected Russian-speaking threat actor has been found weaponizing the two flaws to break into at least 395 organizations in 48 countries, most of them concentrated in the U.S. education sector. The attacks used hundreds of AI agents, powered by OpenAI's Codex harness and a DeepSeek model, to target organizations at scale, while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originates from the IP address "45.142.193[.]132." "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said. In light of active exploitation efforts, it's imperative that users apply the latest fixes for optimal protection. PaperCut customers running an emergency patch build are advised to move to a maintenance release. Found this article interesting? Follow ASMGi on Google News, Twitter and LinkedIn to read more exclusive content ASMGi post.

IT Security News
Sep 1st, 2026
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog.

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. 2026-09-01 11:09 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, [...] Read the original article: U.S. U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This... Security Products & Services July 28, 2025 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains... April 21, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its Known... August 31, 2026 In "Cyber Security News"

News4Hackers
Aug 31st, 2026
Exploited PaperCut vulnerabilities: new details and security flaws.

Exploited PaperCut vulnerabilities: new details and security flaws. Post Views: 15 PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems. Overview of the vulnerabilities. PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems. The flaws allow unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code remotely on affected systems. The vendor released a security advisory on August 27 and deployed the first emergency patch the following day for PaperCut NG/MF versions 25 and 26. A second update was released later that same day to address additional risks, including for version 24. Key vulnerabilities identified. CVE-2026-81578. One, tracked as CVE-2026-81578, is a high-severity authentication bypass that enables remote, unauthenticated users to alter specific system configurations. CVE-2026-82078. The second, CVE-2026-82078, involves unsafe dynamic class loading within database connection utilities. The advisory explained that compromising system configuration parameters could allow execution of arbitrary Java bytecode from the application classpath within the PaperCut server's security context. Security implications and response. Indicators of compromise (IoCs) related to the vulnerabilities have been published. Initial reports suggested a single flaw was being exploited, but subsequent analysis by PaperCut and security firms Huntress and WatchTowr confirmed two distinct zero-day vulnerabilities. WatchTowr identified multiple methods to bypass the initial patch and an additional authentication flaw, prompting the second update. Huntress confirmed attacks on at least two clients, with the first exploitation attempts detected on August 26. The firm reported that the activity centered on system reconnaissance, without evidence of secondary malware or further command-and-control interactions. Current status and recommendations. The identity of the attackers and their objectives remain unknown. However, prior incidents involving PaperCut vulnerabilities highlight the risks, as CISA's Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been linked to ransomware campaigns. ShadowServer Foundation data indicates approximately 1,000 PaperCut installations are accessible online, with the majority located in North America and Europe. The company continues to refine its advisory, emphasizing the need for immediate patching and monitoring for signs of compromise. Security teams are urged to review the provided IoCs and implement mitigations to prevent exploitation.

Bank Info Security
Aug 31st, 2026
Attackers actively exploit flaws in PaperCut NG/MF.

Attackers actively exploit flaws in PaperCut NG/MF. Vendor Issues Second Set of Emergency Patches for Printer Management Software Mathew J. Schwartz (euroinfosec) - August 31, 2026 Widely used print management software vendor PaperCut published two emergency patches as it battles attackers actively exploiting zero-day vulnerabilities in its tools. "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing," the company said in an "urgent security advisory" to customers updated on Monday. The Australian company counts 100 million end users of its software, which is designed to facilitate self-management of printers and multi-function devices, including managing and tracking print queues. The company said the software is used for everything from large enterprise and university environments that may number over 100,000 users to smaller organizations that may facilitate printing for fewer than 50 users on just a handful of printers. "The vulnerabilities allow an unauthenticated attacker to bypass authentication and gain remote-code execution on affected instances. Patches are available, but in-the-wild exploitation is already happening," said cybersecurity firm watchTowr in a Friday LinkedIn post. The vulnerabilities appear to affect all versions of PaperCut NG and MF Application Server. PaperCut on Thursday issued emergency patches for versions 25 and 26, followed Friday by an updated set of patches that also extended coverage to version 24, first released in October 2024. The company released indicators of compromise resulting from in-the-wild attacks that organizations can use to hunt for signs that they've been breached. Cybersecurity firm Huntress on Friday said that nearly half of the roughly 2,500 installations of PaperCut that it tracks were running version 23 - released in October 2023 - or older, for which no patches are available. PaperCut told customers it recommends they upgrade their software. Additional mitigation advice from PaperCut is that any organization that makes any version of the software accessible using the public internet should "immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses)," as well as "use firewall rules, network access controls or equivalent measures to ensure the PaperCut server's web interfaces cannot be reached from untrusted internet addresses." The company's patches address two flaws in the software: CVE-2026-82078, an unsafe dynamic class loading in database connector with a critical CVSS score of 9.4, and CVE-2026-81578, an improper access control vulnerability which exists in the software's web management interface with a high CVSS score of 8.8. After shipping a first batch of patches Thursday, the company on Friday released "Emergency Patch Release 2," which it has advised all customers to install, even if they already installed the first patch. The company said the second patch release "includes additional hardening beyond the original emergency patch," gleaned in part thanks to efforts by researchers at Huntress and watchTowr, and it would help to better protect customers who couldn't mitigate the vulnerabilities by not making their PaperCut software public facing. WatchTowr said that after PaperCut first disclosed the flaws Thursday, it was able to reproduce the vulnerabilities as well as find "multiple patch bypasses," including "an additional authentication bypass vulnerability," all of which it's shared with PaperCut. Huntress said it's also created a working proof-of-concept exploit based on the vulnerabilities, and found at least two of its customers have been targeted with exploits for the flaws, one of them on Wednesday. "Post-exploitation activity included base64-encoded commands executed on the targeted server that decoded to commands whoami and ver that aimed to identify the victim's user account and operating system," it said. These aren't the first serious flaws to be found in PaperCut's printer management software. The catalog of known exploited vulnerabilities maintained by the U.S. Cybersecurity and Infrastructure Security Agency features multiple PaperCut NG/MF vulnerabilities, including CVE-2023-27350, an improper access control vulnerability added in 2023 when it was being targeted by ransomware-wielding attackers, as well as CVE-2023-2533, a cross-site request forgery vulnerability added in 2025. On April 20, CISA also added to its KEV catalog CVE-2023-27351, an improper authentication vulnerability in PaperCut NG/MF. The agency warned at the time that the flaw was already being actively exploited by ransomware-wielding attackers.

Falcon Internet
Aug 29th, 2026
PaperCut zero-day under active attack: two emergency patches in 48 hours.

PaperCut zero-day under active attack: two emergency patches in 48 hours. If your organization runs PaperCut NG or PaperCut MF - and with 100 million users at over 70,000 organizations worldwide, there's a real chance it does - stop what you're doing and check your patch level. On August 27, 2026, PaperCut published an urgent security advisory confirming active exploitation of two previously unknown vulnerabilities in its print management software. Emergency patches followed, and then a second round of emergency patches the very next day after researchers identified bypasses in the first fix. The window between disclosure and exploitation was essentially zero: attackers were already inside customer environments when the advisory dropped. What PaperCut is and why this matters. PaperCut NG and PaperCut MF are among the most widely deployed print management platforms in the world, handling print tracking, cost control, and device management across Windows, Linux, and macOS environments. The software is especially prevalent in education, healthcare, and small-to-midsize businesses - exactly the organizations that tend to have fewer people watching their logs at 2 a.m. when an attacker runs whoami on a production server. According to the vendor, 41 percent of its customer base is small businesses. These aren't Fortune 500 shops with a SOC team; they're the kind of organizations whose print server runs quietly in a back office and never makes the vulnerability-management queue. The attack chain: two flaws, zero credentials. Two CVEs are being chained together to produce unauthenticated remote code execution: * CVE-2026-81578 (CVSS 8.8 - High): An improper access control vulnerability in PaperCut's web management interface. The flaw arises from a page-rendering mismatch: PaperCut's authorization check trusts the rendered page but fails to verify the permissions required by the back-end component actually executing the action. An unauthenticated attacker can send a specially crafted request that routes through the authorization check without tripping it, then triggers administrative functions - including configuration writes - on the server. * CVE-2026-82078 (CVSS 9.4 - Critical): An unsafe dynamic class-loading vulnerability in PaperCut's database connection utilities. The application instantiates database driver classes based on a configurable driver name, without validating those names against any allowlist. Once an attacker has used CVE-2026-81578 to write a malicious driver reference into a configuration file, CVE-2026-82078 loads and executes arbitrary Java bytecode - giving the attacker arbitrary code execution under the PaperCut application server's service account, which in default Windows installations runs as SYSTEM. Huntress researchers confirmed the chain works in practice, developing a proof-of-concept exploit that spawned charmap.exe processes running as SYSTEM under the PaperCut server process. The attack is fully pre-authentication. What attackers are actually doing. Huntress observed confirmed exploitation in two customer environments. Post-exploitation activity was consistent with initial reconnaissance: hex-encoded Java .class files (named Udydn.class and Moo97.class) were deployed to the server, executing system discovery commands including whoami & ver and tasklist, writing output to files, then deleting logs and themselves to cover their tracks. The cleanup behavior suggests deliberate operational security on the attacker's part - this wasn't opportunistic noise. A reliable forensic indicator is a suspicious log entry containing DB URL: jdbc:derby:memory:pwn alongside irregular Apache Derby database boot messages. If you're searching logs and see that string, treat it as confirmed compromise and begin incident response immediately. The patch situation: read this carefully. PaperCut released its first emergency patch on August 27-28 for NG and MF versions 25 and 26, with version 24 patches following shortly after. If you applied that first patch and stopped there, you may not be fully protected. On August 28, PaperCut released Emergency Patch Release 2 after researchers at watchTowr and Huntress identified multiple methods to bypass the initial fix. Release 2 includes additional hardening beyond the original patch, developed collaboratively with both firms. This is the build you need to be running right now. Affected scope: all versions of PaperCut NG and MF prior to August 27, 2026. Patches are available for versions 24, 25, and 26 on Windows, Linux, and macOS. If you are running version 23 or earlier, no patch is available for your release - upgrade to a current supported version immediately. Patched version numbers for PaperCut version 25: 25.0.12.76497 (NG) and 25.0.12.76496 (MF). Confirm your exact build number in the PaperCut admin interface under About before assuming you are protected. What to do right now. * Patch to Emergency Patch Release 2 immediately. Verify the exact build number, not just the version banner. * Take PaperCut off the public internet. The application server should be accessible only from trusted internal networks or via VPN. There is no legitimate reason to expose a print management interface to the open web. * Hunt for the compromise indicator. Search application and server logs for jdbc:derby:memory:pwn and for unexpected Derby database boot events. Also look for unknown .class files dropped to the PaperCut server directory and for charmap.exe spawned from the PaperCut process. * Preserve evidence before patching if you find indicators. Copy server logs, configuration files, and process tree snapshots before applying patches - forensic data is overwritten quickly, and you'll want it for incident response. * Audit service account privileges. If PaperCut runs as SYSTEM or a highly privileged domain account on your Windows systems, consider constraining that account to a dedicated low-privilege service identity as a long-term hardening measure. The pattern worth noting. PaperCut went through an almost identical situation in 2023, when CVE-2023-27350 and CVE-2023-27351 were exploited before many organizations could patch. The lesson then, as now, is that print management servers - quiet infrastructure that nobody thinks about - are exactly what attackers target for initial access. They're typically trusted on the internal network, often run with elevated privileges, and rarely appear on penetration testing scope lists. At Falcon Internet, seeing servers like this exploited is part of why its NOC monitors for anomalous process trees, not just perimeter alerts. Apply Release 2. Check your logs. If you haven't explicitly restricted your PaperCut management interface to an internal-only network segment, do that now, before you do anything else.

Recently Posted Jobs

Sign up to get curated job recommendations

PaperCut is Hiring for 8 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →