ZeroHour
Huntresspublished ()ingested

PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

criticalExploit / PoC exploited in the wildimportance 82
AI summary · glm-5.3-flash

PaperCut NG/MF hit by a pre-auth RCE zero-day under active exploitation; Huntress reproduced the chain and urged immediate patching.

Huntress reports active exploitation of a zero-day in PaperCut NG and PaperCut MF, and says it reproduced a pre-authentication remote code execution chain. The flaw allows unauthenticated attackers to execute code on exposed PaperCut servers. Huntress published urgent patching, exposure-reduction, and detection guidance. No CVE identifier was provided in the announcement.

  • Pre-auth RCE chain reproduced by Huntress researchers
  • Active exploitation observed in the wild
  • Affects PaperCut NG and PaperCut MF enterprise print management
  • Urgent patching, exposure, and detection guidance published
Full article

PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.

This source does not provide full text. Read it at huntress.com.