HomeSecurityCISA warns of PaperCut RCE vulnerability exploitation

CISA warns of PaperCut RCE vulnerability exploitation

CISA has issued an urgent warning about a critical RCE vulnerability in the PaperCut NG/MF, which malicious actors are actively exploiting in ransomware campaigns.

See also: ManageEngine Exchange Reporter Plus vulnerability allows RCE

PaperCut RCE

The vulnerability, tracked as CVE-2023-2533, poses a serious security risk to organizations worldwide using affected versions of the software. CVE-2023-2533 is classified as a Cross-Site Request Forgery (CSRF) vulnerability and affects PaperCut NG/MF installations. The vulnerability, which falls under the CWE-352, could allow attackers to modify security settings and execute arbitrary code on vulnerable systemsunder certain circumstances.

The severity of the vulnerability lies in its remote code execution (RCE) capability, making it an attractive target for cybercriminals seeking permanent access to corporate networks. The technical nature of this RCE vulnerability means that attackers can trick authenticated users into performing unintended actions in the PaperCut application.

See also: Critical vulnerability in Roundcube allows RCE execution

When successfully exploited, the vulnerability allows attackers to modify critical security settings and potentially deploy malicious code across the entire affected print management infrastructure.

CISA warns of PaperCut RCE vulnerability exploitation
CISA warns of PaperCut RCE vulnerability exploitation

The combination of social engineering and technical exploitation makes the vulnerability particularly dangerous in corporate environments, where print management systems often have elevated network access privileges

CISA added vulnerability CVE-2023-2533 to the Known Exploited Vulnerabilities (KEV) list on July 28, 2025, setting a mandatory remediation deadline of August 18, 2025 for federal agencies.

This three-week timeframe reflects the criticality of the threat and its active exploitation that has already been observed online.

See also: RD Gateway UAF vulnerability allows RCE

Federal agencies must either implement the fixes provided by the manufacturer, follow the relevant instructions in Binding Operational Directive (BOD) 22-01 for cloud services , or discontinue use of the product if effective remediation measures are not in place.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS