Critical PaperCut Vulnerability Under Active Attack Triggers CISA Emergency Alert


# CISA Warns of Active Exploitation in PaperCut Print Management Software

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog, warning of active attacks targeting the widely-used system.

## The Vulnerability

The security flaw, designated CVE-2023-2533 with a severity score of 8.4, is a cross-site request forgery (CSRF) vulnerability that could allow attackers to execute malicious code remotely. Under specific conditions, threat actors can alter security settings or run unauthorized commands on affected systems.

## Why This Matters

PaperCut NG/MF is extensively deployed across schools, businesses, and government offices to manage printing operations and control network printers. Since the admin console typically operates on internal web servers, a successful exploit could provide attackers with a gateway to broader organizational systems.

## How Attacks Work

Cybercriminals can exploit this vulnerability by targeting administrators with active login sessions. They trick users into clicking malicious links through phishing emails or compromised websites, leading to unauthorized system changes without the admin’s knowledge.

## Threat Landscape

PaperCut software has previously been targeted by Iranian state-sponsored hackers and major ransomware groups including Bl00dy, Cl0p, and LockBit. These groups have used similar vulnerabilities as initial entry points for larger attacks.

## Protection Measures

Organizations should immediately:
– Apply available security patches
– Review and adjust session timeout settings
– Restrict administrative access to known IP addresses
– Implement strong CSRF token validation
– Monitor for suspicious activities using MITRE ATT&CK techniques T1190 and T1071

## Compliance Requirements

Federal agencies must update their PaperCut installations to patched versions by August 18, 2025, according to CISA’s Binding Operational Directive 22-01.

The active exploitation of this vulnerability underscores the importance of maintaining current security patches and implementing comprehensive defense strategies for print management systems.

Share This Article