PaperCut released consolidated security patches Thursday that supersede multiple emergency updates addressing two actively exploited vulnerabilities in its document management software. The new maintenance releases affect PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10.

The move consolidates disparate emergency patches into single, unified releases. PaperCut opted for this approach rather than continue distributing incremental fixes, streamlining deployment across customer environments. This matters because organizations running PaperCut NG or MF software now have one clear upgrade path instead of chasing multiple patch sequences.

PaperCut's core product manages print services, document workflows, and related infrastructure for enterprises, government agencies, educational institutions and managed service providers. Hundreds of thousands of installations worldwide depend on this software to control access, track usage, and bill print jobs. Active exploitation of flaws in this layer creates exposure across entire organizations.

The company disclosed that both vulnerabilities had reached active exploitation in the wild before patches arrived. Active exploitation means threat actors publicly demonstrated attacks or were observed targeting customers in real conditions. This classification elevates urgency since patching delays compound organizational risk.

PaperCut did not name specific CVE identifiers in the maintenance release announcement, but the company identified that two distinct security flaws drove the emergency response. Details typically emerge as vendors publish formal security advisories with CVE numbers and CVSS scores.

Organizations using PaperCut NG or MF should prioritize updating to the designated versions immediately. The software manages critical infrastructure in corporate networks. Delay introduces risk of unauthorized print access, document theft, credential compromise, or lateral movement into broader systems. Educational institutions and government agencies face particular pressure since these sectors operate tightly managed patch windows but manage centralized PaperCut deployments across hundreds of endpoints.

Migration from emergency patches to maintenance releases simplifies validation. IT teams no longer need to verify multiple sequential patch applications or track which emergency update version a given system received. The unified maintenance release approach reduces configuration drift and deployment errors that often accompany multi-step patching sequences.

PaperCut's shift from emergency to regular maintenance releases signals confidence that the underlying code now blocks both exploitation paths. The company typically maintains separate release tracks for its three most recent major versions, explaining why fixes span versions 26.x, 25.x and 24.x. Organizations still running earlier versions lack official patches and face elevated risk.

Managed service providers delivering PaperCut as a shared service face heightened responsibility. A single vulnerable instance can expose multiple customers simultaneously. MSPs should treat this update as blocking and coordinate deployment across client environments without delay.

The software vendor runs on Windows and Linux servers, integrating with directory services, cloud storage and billing systems. This integration depth means vulnerabilities in PaperCut can cascade into related infrastructure if exploited. Proper network segmentation between PaperCut systems and sensitive backend services limits blast radius if compromise occurs before patching completes.

Organizations should download and test the maintenance releases in non-production environments first, then roll out sequentially across their infrastructure. Parallel deployment strategies work for smaller deployments but risk service interruption if issues emerge. Validation testing remains essential despite the vendor's quality assurance processes.