PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

Summary

PaperCut has released new maintenance releases for its NG/MF software that address two security flaws that have been actively exploited. The new versions (26.0.5, 25.0.13, and 24.1.10) replace previously issued emergency patches for these vulnerabilities.

IFF Assessment

FOE

The active exploitation of vulnerabilities in widely used software like PaperCut poses a direct threat to organizations, making this bad news for defenders.

Severity

9.8 Critical (AI Estimated)

The article states the flaws are 'actively exploited,' indicating a high likelihood of successful exploitation. Given the nature of patching emergency fixes with standard releases, the vulnerabilities likely allow for significant impact, such as remote code execution or unauthorized access, hence a critical score.

Defender Context

Organizations using PaperCut software must prioritize updating to the latest maintenance releases (26.0.5, 25.0.13, and 24.1.10) to mitigate the risk of exploitation. The fact that these flaws were actively exploited before a stable fix was available highlights the importance of prompt patching and threat intelligence for deployed software.

Read Full Story →