What We Know
PaperCut released a second emergency security update for two vulnerabilities affecting its NG and MF print-management solutions after threat actors exploited them against users.3Backed by 3 sourcesBleepingComputersecurityweek.comcybersecuritydive.com The vulnerabilities are described in reporting as two chained zero-day flaws, meaning attackers may combine them to carry out an attack rather than exploit either issue in isolation.2Backed by 2 sourcescybersecuritydive.comseveritydaily.com
PaperCut’s second emergency patch follows an earlier emergency fix that did not stop the full exploit chain, according to reporting on the vulnerabilities.1Backed by 1 sourcesseveritydaily.com Security researchers and incident responders have characterized the flaws as critical and exploited in the wild, making affected organizations’ patching and investigation efforts especially urgent.1Backed by 1 sourcesrapid7.com
A security response guide frames PaperCut’s second patch as part of an urgent response to two zero-day vulnerabilities.1Context from one sourcevijilan.com
Source Comparison
Aligned reportingCorroborates
- BleepingComputer↗Reports PaperCut’s second emergency update for two actively exploited vulnerabilities affecting its NG and MF print-management products.
- securityweek.com↗Describes a second emergency patch for zero-day vulnerabilities exploited against users of PaperCut’s NG and MF print-management solutions.
- cybersecuritydive.com↗Connects PaperCut’s emergency patches with threat actors targeting chained vulnerabilities, supporting both the second-patch account and the description of a chained exploit.
- severitydaily.com↗Reports that PaperCut’s zero-day comprises two chained CVEs and that the first emergency patch did not stop the chain.
- rapid7.com↗Characterizes the PaperCut NG/MF issue as a critical zero-day exploited in the wild, supporting the reported severity and active exploitation.