
PaperCut Releases Second Emergency Patch for Exploited Flaws in Print Management Software
SecurityCVE-2023-27350CVE-2023-27351PaperCutPrintManagementRemoteCodeExecutionAuthenticationBypassRansomwarePatchExploit
PaperCut released a second emergency security update for actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers identified bypasses for the initial fixes. The flaws, tracked as CVE-2023-27350 and CVE-2023-27351, allow unauthenticated remote code execution and authentication bypass, enabling attackers to gain full system control. The vulnerabilities affect versions 8.0.0 to 22.0.4 of PaperCut MF/NG, with the first patch issued in March 2023 and the second in April 2023. Exploitation has been observed in the wild, with threat actors deploying ransomware and other malware. Organizations are advised to apply the latest patches immediately to mitigate risks.