PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
AI summary · glm-5.3-flash
PaperCut NG/MF hit by a pre-auth RCE zero-day under active exploitation; Huntress reproduced the chain and urged immediate patching.
Huntress reports active exploitation of a zero-day in PaperCut NG and PaperCut MF, and says it reproduced a pre-authentication remote code execution chain. The flaw allows unauthenticated attackers to execute code on exposed PaperCut servers. Huntress published urgent patching, exposure-reduction, and detection guidance. No CVE identifier was provided in the announcement.
- Pre-auth RCE chain reproduced by Huntress researchers
- Active exploitation observed in the wild
- Affects PaperCut NG and PaperCut MF enterprise print management
- Urgent patching, exposure, and detection guidance published
Full article
PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.
This source does not provide full text. Read it at huntress.com.