PaperCut Replaces Emergency Patches with Maintenance Release for Two Actively Exploited Vulnerabilities
What Happened — PaperCut published a regular maintenance release (NG/MF v26.0.5, v25.0.13, v24.1.10) that supersedes the emergency patches previously issued for two security flaws that are currently being exploited in the wild.
Why It Matters for Trust & Control Assurance
- Continuous vulnerability monitoring and a formal patch‑management workflow are essential to prevent a gap between emergency fixes and documented change control.
- Maintaining auditable evidence of patch deployment satisfies the “timely remediation of known weaknesses” control objective that maps to many frameworks (e.g., NIST CSF 2.0).
- Relying on ad‑hoc emergency patches without a repeatable process can leave an organization exposed to compliance findings and audit questions.
Who Is Affected – Enterprises, schools, hospitals, and other organizations that run PaperCut NG or MF for print‑management services.
Recommended Actions
- Verify that all PaperCut endpoints are upgraded to the latest maintenance release.
- Integrate vendor security advisories (including PaperCut’s) into your automated vulnerability‑management tooling.
- Record patch‑deployment dates, version numbers, and validation results in a central evidence store for audit readiness. Source: The Hacker News
Technical Notes – The two flaws are being actively exploited; the vendor has not disclosed CVE identifiers in the public advisory, but they are described as remote‑code‑execution vectors affecting the print‑management server component. Source: same as above