CISA has issued an urgent warning regarding a critical vulnerability in PaperCut NG/MF print management software that threat actors are actively exploiting in ransomware campaigns. This combination of social engineering and technical exploitation makes the vulnerability particularly dangerous in enterprise environments where print management systems often have elevated network privileges. CVE-2023-2533 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that affects PaperCut NG/MF software installations. While CISA has not definitively confirmed the vulnerability’s use in ransomware campaigns, the “Unknown” status regarding ransomware deployment does not diminish the critical nature of this security flaw. Federal agencies must either apply vendor-provided mitigations, follow applicable Binding Operational Directive (BOD) 22-01 guidance for cloud services, or discontinue use of the product if effective mitigations remain unavailable. The vulnerability, tracked as CVE-2023-2533, represents a significant security risk to organizations worldwide using the affected software versions. The vulnerability’s severity stems from its ability to enable remote code execution (RCE), making it an attractive target for cybercriminals seeking to establish persistent access to enterprise networks.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 29 Jul 2025 09:50:16 +0000