PaperCut Releases Official Fixes for Actively Exploited Vulnerabilities
PaperCut has replaced its emergency patches with official maintenance releases addressing two flaws under active exploitation. Organizations are urged to update immediately.
TL;DR
- PaperCut released new maintenance updates to replace previous emergency patches.
- Two actively exploited vulnerabilities are now addressed in versions 26.0.5, 25.0.13, and 24.1.10.
- Organizations using PaperCut NG/MF should upgrade immediately to mitigate risk.
- The updated releases offer more stable and comprehensive fixes than prior interim solutions.
- This underscores the importance of timely patch management for print management software.
PaperCut has rolled out new maintenance releases that supplant earlier emergency patches issued to counteract two security flaws currently being exploited in the wild. The update aims to provide organizations with more reliable and thoroughly tested remediations.
The newly available versions—26.0.5, 25.0.13, and 24.1.10—are designated as Regular Maintenance Releases (MR), offering improved stability over the previously distributed hotfixes. This move ensures that users can maintain secure deployments without relying on temporary mitigations.
With active exploitation reported, IT administrators managing PaperCut NG/MF environments should prioritize deployment of these updates to reduce exposure and strengthen their security posture.
Vulnerability Response Overview
- Emergency patches were initially deployed to curb ongoing attacks exploiting two critical flaws.
- Following further analysis and testing, PaperCut transitioned to full maintenance releases for better reliability.
- Versions 26.0.5, 25.0.13, and 24.1.10 contain the finalized fixes and additional improvements.
Recommended Actions for Administrators
- Immediately upgrade PaperCut NG/MF installations to the latest maintenance releases.
- Verify that systems are not exhibiting signs of compromise consistent with known exploit patterns.
- Review network logs for unusual activity potentially linked to the exploited vulnerabilities.
- Ensure future patch compliance through automated update policies where feasible.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.