PaperCut NG MF active exploitation is confirmed by PaperCut, and administrators should treat patching and compromise investigation as two separate jobs. PaperCut says it is aware of confirmed customer incidents involving PaperCut NG and MF. If an Application Server is exposed to untrusted networks, restrict access, install Emergency Patch Release 2, update the relevant PaperCut server roles and then investigate whether exploitation may have occurred before mitigation.
Direct answer: installing the first emergency patch is no longer the complete response. PaperCut recommends Emergency Patch Release 2 even for systems that already received the original emergency patch. Administrators should also investigate previous exposure using the vendor’s current compromise indicators. The absence of those indicators does not prove that a system was unaffected.
What changed in the PaperCut NG/MF incident?
PaperCut’s security bulletin describes active exploitation affecting PaperCut NG and MF and says the company is aware of confirmed customer incidents. The response evolved quickly from an initial emergency patch to Emergency Patch Release 2, which adds further protections and is the current emergency mitigation described by the vendor for supported v24, v25 and v26 environments.
The vendor has also expanded its compromise-investigation guidance. That means an administrator who patched earlier should not stop at checking whether an update was installed. The separate question is whether the server may have been compromised before the mitigation was applied.

What should a PaperCut administrator do now?
1. Reduce untrusted exposure
If the PaperCut Application Server web interface is reachable from untrusted networks, follow PaperCut’s current guidance to restrict access to trusted IP addresses while remediation is being completed.
2. Identify every relevant PaperCut server role
Do not evaluate only the primary Application Server. PaperCut’s guidance also covers other relevant server roles such as Site Servers and secondary or print servers that need a patched version.
3. Install Emergency Patch Release 2
Use the current Release 2 package for the supported branch you operate. PaperCut recommends Release 2 even if the original emergency patch was installed previously.
4. Verify the patched state
Confirm that the intended PaperCut servers actually received the correct patched build and that no required server role was missed.
5. Investigate prior compromise separately
Review PaperCut logs, host activity and security telemetry against the vendor’s current investigation guidance rather than assuming that successful patch installation proves the server was previously clean.
6. Escalate suspicious findings
If investigation finds suspicious PaperCut log activity, unexpected files, unusual child processes or remote-access software consistent with the vendor’s current indicators, preserve evidence and follow your organisation’s incident-response process.
Do you still need Release 2 if Release 1 was installed?
Yes. PaperCut says customers should install Emergency Patch Release 2 even if they already installed the original emergency patch. Release 2 is therefore the current emergency-patch target in the reviewed bulletin rather than Release 1.
Which PaperCut versions have Emergency Patch Release 2?
The reviewed vendor guidance provides Release 2 for supported PaperCut NG/MF v24, v25 and v26 environments. Administrators should use the current vendor package and instructions for their own branch rather than assuming that one installer or build applies to every deployment.
Do Site Servers and secondary servers also need attention?
Yes. PaperCut’s current guidance says administrators should make sure relevant PaperCut server roles are running a patched version. This includes Site Servers and secondary or print servers where they are part of the deployment.
How can you check whether PaperCut was already compromised?
PaperCut has published investigation guidance covering several types of evidence. Administrators should review the vendor’s current bulletin alongside their own host and security telemetry because no single indicator is a complete compromise test.
Examples disclosed by PaperCut include suspicious strings in server.log, unexpected files with extensions such as .class, .cmd and .out, and unusual situations where the PaperCut pc-app process launches shell or command processes. The bulletin also describes observed reconnaissance and remote-access activity in investigated incidents.
These indicators should be treated as evidence to investigate, not as a universal checklist that every attacker must leave behind.
Does finding no listed indicator mean the server is safe?
No. PaperCut explicitly warns that the absence of its published indicators does not establish that a system was unaffected. This is important because an organisation can patch successfully and still need to investigate the period when the server was exposed and vulnerable.
What if Card/ID lookup stops working after patching?
PaperCut says it received reports that external-database Card/ID lookup was not working as expected for some patched deployments. For environments using the older jTDS SQL Server driver for external Card/ID lookup, the vendor provides configuration guidance to move to the supported Microsoft SQL JDBC driver as a first troubleshooting step.
This issue does not change the underlying active-exploitation state. Do not treat an application problem after patching as evidence that an exposed vulnerable build should be restored.
What about SAML problems after the emergency patch?
PaperCut also reported investigating SAML behaviour that was not working as expected for some customers after patching. A complete vendor-confirmed SAML resolution was not established in the reviewed bulletin.
TPS therefore does not recommend inventing a workaround, disabling a security control or rolling back the emergency mitigation. Administrators affected by the SAML issue should use PaperCut’s latest vendor guidance and their organisation’s change and incident-management procedures.
Is Emergency Patch Release 2 the final normal PaperCut release?
No. PaperCut describes Release 2 as an emergency patch and says it is working toward an official release. Administrators should therefore continue to watch the bulletin for a normal fixed release or further emergency guidance.
What remains unresolved?
- The total number of compromised organisations has not been established.
- No reliable India-specific victim or exposure count was established.
- Campaign attribution and the complete exploitation path across every incident remain unresolved.
- The published indicators are not guaranteed to detect every compromise.
- A complete vendor-confirmed resolution for the reported SAML problem was not established in the reviewed bulletin.
- The final normal PaperCut release replacing the emergency-patch workflow was still pending.
Verification note
ThePulseSignal reviewed PaperCut’s current urgent security bulletin for the active-exploitation statement, Emergency Patch Release 2 instructions, server-role guidance, compromise indicators and reported post-patch Card/ID and SAML issues. Supporting security advisories and incident-response reporting were used to corroborate the current risk and remediation context.



