Latest patches are always cumulative for 3rd party. Once 2.y is released it will include the previous fixes cumulatively, whatever were present 2.x or lower versions. The only exceptions being the vendor is maintaining multiple version ranges, mostly happens with developments tools like Java, Python or Wireshark. If the vendor maintains multiple simultaneous ranges, then we would upgrade to the same range. Fore example if as of today Java 8 and 11 both are supported and are maintained, if your machine has 8.x we upgrade to latest version of 8.x, similarly if you have vulnerable 11.x we would migrate you to latest version of 11.x.