What Happened
Print management vendor PaperCut released two emergency patches due to active exploitation of zero-day vulnerabilities in PaperCut NG and PaperCut MF. The attack targeted widely used print applications, with nearly half of installations running unsupported versions at the time of disclosure.
Timeline
Initial Exploitation: Attackers began exploiting zero-day vulnerabilities in PaperCut NG and PaperCut MF before public disclosure.
Vendor Response: PaperCut released emergency patches for both products.
Disclosure: The company confirmed active exploitation was underway, triggering urgent customer notifications.
Major Nonconformity: Analysis revealed that nearly 50% of PaperCut installations were running unsupported versions, meaning they couldn't receive the emergency patches without first upgrading their base software.
Which Controls Failed or Were Missing
Vulnerability Management Process Breakdown
The incident exposed three control failures that ISO/IEC 27001:2022 Annex A and SOC 2 explicitly address:
Version Control and Lifecycle Management: Organizations running unsupported versions violated basic vulnerability management practices. When the emergency patches were released, these teams faced a two-step remediation: upgrade to a supported version, then apply the security patch. This process isn't a quick fix; it's a multi-day project requiring testing, change approval, and deployment windows.
Asset Inventory Accuracy: You can't patch what you don't know you have. The 50% unsupported installation rate suggests organizations lacked accurate software asset inventories. If your CMDB doesn't flag end-of-life software versions, you're building risk you can't see.
Compensating Controls During Patching Delays: Zero-day exploitation doesn't wait for your change control board to meet. Organizations needed network segmentation, application-layer filtering, or access restrictions to limit exposure while patches were tested and deployed. The absence of these compensating controls left print management systems as undefended entry points.
What the Relevant Standards Require
ISO/IEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities
This control requires organizations to obtain timely information about technical vulnerabilities, evaluate exposure, and take appropriate measures. Specifically:
- Maintain an inventory of assets and associated vulnerabilities
- Define roles and responsibilities for vulnerability management
- Establish timelines for vulnerability assessment and remediation
- Implement compensating controls when patches can't be applied immediately
Running unsupported software versions violates the fundamental premise of this control. You can't manage vulnerabilities in software the vendor no longer supports.
SOC 2 CC7.1: System Monitoring
The Common Criteria require that "the entity monitors the system and takes action to address identified deficiencies." This includes:
- Monitoring infrastructure and software for vulnerabilities
- Detecting anomalous activity that could indicate exploitation
- Implementing a process to deploy security patches in a timely manner
If your monitoring didn't flag the unsupported PaperCut versions before the zero-day disclosure, your CC7.1 control isn't operating effectively.
ISO/IEC 27001:2022 Annex A 5.23: Information Security for Use of Cloud Services
Print management often integrates with cloud services. This control requires organizations to establish processes for managing security in cloud-based or SaaS deployments, including:
- Regular review of service provider security practices
- Monitoring of security updates and patches from providers
- Incident response coordination with service providers
If you're running PaperCut as a managed service, your vendor relationship controls should have flagged the version currency issue.
Lessons and Action Items for Your Team
1. Audit Your Software Asset Inventory This Week
Pull a report of every application in your environment. Flag anything running on an unsupported version. If you don't have this data in a CMDB, you're not ready for the next zero-day.
Specific action: Query your asset management system for software with end-of-support dates in the past. Escalate every hit to your risk register.
2. Define Your Compensating Control Playbook
You need a documented decision tree: "When we can't patch immediately, we do X." That might be:
- Network isolation (move the vulnerable system to a restricted VLAN)
- Application firewall rules (block specific request patterns)
- Access restriction (disable external access until patching is complete)
- Enhanced monitoring (deploy IDS signatures for known exploit patterns)
Specific action: Draft a one-page compensating control matrix. Map each control type to the team that implements it and the maximum acceptable duration.
3. Treat Unsupported Software as a Major Nonconformity
If your internal audit finds unsupported software in production, classify it as a major nonconformity under ISO/IEC 27001 or a significant deficiency under SOC 2. This isn't pedantic; it's accurate. You can't meet Annex A 8.8 requirements if the vendor isn't publishing patches.
Specific action: Add "software version currency" to your internal audit checklist. Require remediation plans with executive sponsorship for anything out of support.
4. Build Patch Testing Into Your Sprint Cycles
Emergency patches break things. You need a test environment and a process that can validate a patch in hours, not days. If your change control process requires a two-week lead time for security patches, you're designing in delay.
Specific action: Establish a "security patch fast track" in your change management policy. Define criteria (active exploitation, CVSS score above 8.5, internet-facing system) that trigger accelerated approval.
5. Map Print Infrastructure to Your Risk Treatment Plan
Print management systems touch authentication (directory services), data (document content), and network access (printer discovery protocols). Treat them as Tier 2 assets at minimum.
Specific action: Add print management systems to your next scenario-based risk assessment. Model the impact of credential theft, data exfiltration, or lateral movement from a compromised print server.
The PaperCut incident isn't exotic. It's the predictable outcome of letting software drift out of support while connected to production networks. Your auditor will ask about vulnerability management. Your answer needs to include version currency, compensating controls, and evidence that you can patch under pressure.



