• PaperCut released versions 26.0.5, 25.0.13 and 24.1.10 on 10 September, moving earlier security fixes into regular maintenance builds
  • PaperCut says Emergency Patch Release 3 already provides protection, while relevant application, site and secondary servers still need to be accounted for

The fact

PaperCut released NG and MF versions 26.0.5, 25.0.13 and 24.1.10 on 10 September, moving fixes from its earlier emergency patches into regular maintenance builds. The releases came before CISA's 14 September remediation deadline for US federal civilian agencies covering CVE-2026-82078, which PaperCut says can be chained with CVE-2026-81578.

PaperCut says customers still using Emergency Patch Release 1 or 2 should update immediately. Systems running Emergency Patch Release 3 are already protected against the issues described in the advisory and can move to the maintenance releases through their normal update schedule.

The earlier emergency builds kept their original version numbers, which meant PaperCut's in-product notice could not distinguish patched servers from unpatched ones. The new maintenance releases have their own version numbers. PaperCut also says relevant site and secondary servers must be updated; its user-client software is not affected by this advisory.

The assessment

PaperCut's emergency rollout created an awkward record-keeping problem. Because the emergency builds kept the original version number, two servers could show the same version even if they had received different emergency patches. After three releases in quick succession, a ticket that simply says "patched" does not tell the next administrator enough.

The 10 September maintenance builds make that easier because each supported branch now has a clear version number. But checking the main application server is only part of the job. Site and secondary servers also need to appear in the update record, or a deployment can still contain machines whose status is unclear.

For BTW readers, teams can now separate servers that still need urgent protection from those already running Emergency Patch Release 3 and waiting for a routine maintenance upgrade. A server-by-server build record makes that distinction clear and avoids treating a protected system as unpatched simply because its older version number is still visible.

What to watch

Watch the move from emergency patches to the new maintenance builds across application, site and secondary servers. The useful evidence will be a deployment-wide record showing which machines are on current maintenance releases, which remain protected by Emergency Patch Release 3 and which still need urgent attention.