PaperCut Vulnerabilities and Affected Products
Vulnerabilities associated with Print Deploy.
Products
Clear product- PaperCut NG, PaperCut MF12 vulnerabilities
- papercut_ng8 vulnerabilities
- PaperCut NG/MF7 vulnerabilities
- papercut_mf7 vulnerabilities
- NG4 vulnerabilities
- NG/MF2 vulnerabilities
- PaperCut NG2 vulnerabilities
- Print Deploy2 vulnerabilities
- MF/NG1 vulnerability
- PaperCut Hive1 vulnerability
- PaperCut MF1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6645HIGH | Insecure Search Path Vulnerability in PaperCut Print Deploy Client for WindowsAn insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executabl… CWE-427Jun 22, 2026 | CVSS7.3v4.0 | EPSS0.178% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9785HIGH | Misconfigured certificate validation with self-signed certificates for Print DeployPaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks. It was discovered that certain parts o… CWE-295Sep 3, 2025 | CVSS7.7v4.0 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |