PaperCut is warning customers that attackers are actively exploiting a vulnerability in PaperCut NG and PaperCut MF, according to BleepingComputer. The report cites an urgent PaperCut advisory published Thursday that says the company’s security response team is investigating active exploitation and is aware of confirmed customer incidents. The company’s guidance is focused on exposure. PaperCut is urging organizations with Internet-facing PaperCut Application Servers to immediately restrict access to the products’ web interfaces to trusted IP addresses, using firewall rules or network access controls. BleepingComputer reports that PaperCut says the vulnerability affects all versions of PaperCut NG and PaperCut MF. The company has not disclosed technical details of the flaw, how exploitation works, who is behind the attacks, what attackers are doing after compromise, or whether any data is being stolen. PaperCut said its security team reproduced the vulnerability using information provided by a university customer, according to the report. The company has released emergency patches for customers with public-facing PaperCut NG/MF servers who cannot take other mitigating action. The advisory also includes indicators of compromise. BleepingComputer reports that PaperCut told administrators to look for suspicious activity involving the legitimate PaperCut pc-app.exe process, as well as server.log files that have been modified, deleted, or are missing. PaperCut also warned that a lack of visible indicators does not mean a server has not been compromised. The incident is notable because PaperCut servers have been targeted before after vulnerability disclosures. BleepingComputer notes that in April 2023, attackers exploited CVE-2023-27350, a critical PaperCut flaw that allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers. Microsoft later linked some of those 2023 attacks to the Clop ransomware operation, according to BleepingComputer, and also observed intrusions that led to LockBit ransomware attacks. BleepingComputer reports that Clop later said it used the PaperCut vulnerabilities for initial access to victim networks rather than to directly steal archived documents from PaperCut servers. For now, this is an emergency-response story rather than a fully attributed campaign. The confirmed operational facts are that PaperCut says exploitation is active, all NG and MF versions are affected, public-facing servers are the immediate risk surface, and customers should either restrict web access or apply the emergency patches where other mitigation is not possible. Who benefits: Organizations that can quickly remove PaperCut web interfaces from broad Internet access have the clearest mitigation path. Administrators also benefit from PaperCut’s published compromise indicators, though the company cautions they are not definitive proof of safety. Who's exposed: The exposed group is organizations running PaperCut NG or PaperCut MF with Application Servers reachable from the Internet. PaperCut says all versions of those products are affected, according to BleepingComputer.