Summary
- PaperCut has released versions 26.0.5, 25.0.13, and 24.1.10 to replace its emergency patches.
- The releases contain the earlier security fixes plus additional hardening and standard QA testing.
- PaperCut continues to investigate active exploitation and says it is aware of confirmed customer incidents.
PaperCut has moved its response to an actively exploited security flaw out of emergency patching, publishing standard maintenance releases that replace the three rapid fixes issued during the developing campaign.
PaperCut NG and MF versions 26.0.5, 25.0.13, and 24.1.10 became available on 10 September. The company said the releases contain all fixes delivered through Emergency Patch Releases 1, 2, and 3, along with additional security hardening, and have completed its normal quality-assurance process.
PaperCut continues to investigate active exploitation and says it is aware of confirmed customer incidents. Organisations running one of the emergency builds are being directed to move to the corresponding maintenance release.
The change is significant because emergency patches solve a different operational problem from ordinary maintenance releases. During an active exploitation event, vendors may need to produce code quickly enough to reduce customer exposure before it has passed through the complete testing cycle normally applied to a product update.
That creates a difficult trade-off for customers. Remaining on a vulnerable build may leave an exposed system open to attack, while deploying an emergency fix introduces change into a production environment with less testing than administrators would usually expect.
Cyber Insider previously reported how PaperCut’s response entered a second wave as exploitation continued, following earlier coverage of the pre-authentication attack route affecting exposed servers.
The maintenance releases narrow that operational dilemma. They do not make an already compromised server trustworthy, but they give organisations a supported build that incorporates the emergency fixes and has been through PaperCut’s standard release testing.
That distinction becomes important during prolonged exploitation campaigns. Initial vulnerability management focuses on stopping new compromise. Once attacks are confirmed, organisations also have to determine whether systems were exposed before the fix was installed and whether suspicious activity indicates an attacker already gained access.
PaperCut’s products are widely used to manage enterprise and education printing environments. Print-management servers can integrate with directory services, user accounts, document workflows, and multifunction devices, giving compromise consequences beyond the apparently narrow function of printing.
The current incident is another reminder that administrative software can sit deeper inside enterprise networks than its product category implies. Attackers increasingly target management platforms, remote-access appliances, file-transfer tools, and other systems whose permissions and connectivity make them useful pivot points.
The maintenance-release stage also shows why patching statistics alone can be misleading during live incidents. An organisation may have “patched” with an emergency build and still need another maintenance event days later. Others may have deferred the emergency patch while testing, only to receive a more stable release after the exposure window has already been open.
PaperCut has continued updating its security bulletin as new information becomes available. It has not published evidence that every vulnerable internet-facing server was compromised, and confirmed incidents should not be generalised into a universal breach assumption.
The immediate remediation path is now clearer than it was during the emergency phase. The harder task is historical: determining whether exposed servers were reached before those protections arrived. As maintenance releases replace the temporary fixes, the incident is moving from urgent vulnerability response towards compromise assessment and longer-term hardening.





