CuraSec

Act active

PaperCut Replaces Emergency Patches for Two Actively Exploited Flaws

2026-09-11 14:58 UTC · The Hacker News · read the source ↗ #papercut#active-exploitation#patch-management
  • Engineer — Act: Two actively exploited flaws in PaperCut NG/MF now have proper maintenance releases; patch to version 26.0.5, 25.0.13, or 24.1.10 depending on your supported branch — emergency patches are superseded and these are the authoritative fixes.
  • SOC/IR — Plan: Active exploitation is confirmed but the item provides no IOCs, TTPs, or detection signatures; plan to review PaperCut server logs and vendor advisory for exploitation indicators, and prepare a hunt query for abnormal print-server outbound connections once technical details surface.
  • Leader — Plan: Active exploitation of widely deployed print-management software warrants confirming whether PaperCut is in your environment and ensuring the engineering team prioritizes patching this quarter; not a board-level systemic event but relevant if PaperCut is part of your estate.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.