Xerox Delivers Strategic Security Upgrade for FreeFlow Print Server v2 with April 2025 Release
Xerox has unveiled its latest enterprise-grade security update for FreeFlow® Print Server v2, further advancing its position as a leader in secure production printing. Built on Windows® 10, this April 2025 patch—officially released on May 12—goes beyond routine maintenance, representing a critical part of Xerox’s ongoing mission to defend complex print environments from evolving cybersecurity threats.
This quarterly release brings reinforced protection to flagship platforms including the Xerox® iGen® 5 Press, Baltoro™ HF Production Inkjet Press, and Brenva™ HD Production Inkjet Press. With a security-first strategy, Xerox ensures that each update is engineered, tested, and validated across its ecosystem to meet the rigorous standards of today’s print operations.
Quarterly Cadence, Enterprise Confidence
More than just a scheduled patch, Xerox’s April update is part of a disciplined lifecycle strategy—with updates in January, April, July, and October—ensuring long-term security assurance for FreeFlow systems. Every release undergoes exhaustive compatibility testing to guarantee seamless integration, minimizing disruption in mission-critical production environments.
Informed by leading security authorities including the US-CERT advisory council, Xerox’s approach anticipates and neutralizes threats before they can impact customers.
Highlights of the April 2025 Update:
This release replaces the January 2025 patch and includes high-impact software improvements and key component upgrades:
- OpenJDK Java 8 Update 452-b08
- Firefox 137.0.2
- Apache HTTP Server 2.4.63
- Apache Tomcat 6.0.45
- OpenSSL 3.4.0
- OpenSSH 9.9p1
These updates resolve critical Common Vulnerabilities and Exposures (CVEs), including industry-relevant risks like CVE-2025-21191, CVE-2025-26641, and CVE-2025-27477. The updated OpenJDK, Firefox, and OpenSSL packages eliminate multiple known exploits, while the Apache components ensure core service reliability.
Flexible, Secure Deployment Options
Xerox provides multiple deployment methods to align with customers’ unique security environments:
- Offline installation via USB or DVD (ideal for high-security environments)
- Online update via Microsoft Windows® Update or FreeFlow Update Manager
For federal or enterprise users with heightened requirements, Xerox advises using scanned USB media alongside a full system backup and Windows® Restore Point—reinforcing Xerox’s commitment to minimizing operational risk.
Security Behavior Notes:
- SFTP Enforcement: Systems will now block SFTP connections using outdated cryptographic protocols. Only applications compliant with SHA2 and AES 512-bit encryption will be accepted. The Xear Flex app has been aligned accordingly but must be used under the “High” security profile setting.
- Peripheral Access Assurance: Setting “High” security does not disable essential media access (e.g., USB, DVD), preserving operational flexibility. Customers should adapt this feature to match their organizational policies.
Customer-Centric Guidance
Xerox encourages its clients to regularly assess their cybersecurity readiness and engage Xerox Service for assisted updates. For teams with advanced IT capabilities, the FreeFlow Update Manager offers full autonomy while preserving patch integrity.
Whether guided by security compliance or performance optimization, Xerox’s hybrid approach empowers every customer to deploy updates with confidence.
A Future-Proof Commitment
In an era of constant cyber threats, Xerox reaffirms its leadership through precision-crafted, future-focused updates. The April 2025 release continues to set the benchmark for what enterprise print security should look like—proactive, resilient, and deeply aligned with customer success.




