Security Advisory: PaperCut NG/MF Security Bulletin
Kyocera Document Solutions ANZ 2 min read Sep 29, 2026, 1:44:40 PM
We'd like to make you aware of a new security bulletin from PaperCut, published on 24 September 2026. It covers three vulnerabilities in PaperCut NG and PaperCut MF, plus one in the PaperCut Hive embedded app for Ricoh devices. PaperCut has no evidence that any of these have been exploited, and fixes are already available. We recommend applying the update as part of your next maintenance window.
Summary of the Vulnerabilities:
-
CVE-2026-14780 (CVSS 7.5, High): Remote code execution via the Print and Device Scripting feature. It requires an attacker to already have administrator access to PaperCut, and only applies if scripting is enabled. Scripting has been off by default since version 22.1.1.
-
CVE-2026-82077 (CVSS 7.3, High): Remote code execution via the Scan-to-Fax component. It requires an attacker to already have administrator access to PaperCut.
-
CVE-2026-87739 (CVSS 6.9, Medium): Report generation doesn't check user permissions. An unauthenticated attacker could generate reports and view sensitive information.
-
CVE-2026-11744 (CVSS 3.8, Low): A JavaScript injection flaw in the PaperCut Hive embedded app for Ricoh devices. It requires physical access to the device's card reader.
-
The full PaperCut advisory can be found here.
What's Affected:
-
PaperCut NG and PaperCut MF versions earlier than 26.0.5 (or 25.0.13 on the 25.x branch).
-
PaperCut Hive embedded app for Ricoh devices earlier than version 2.3.0.
-
If you've already upgraded to PaperCut NG/MF 26.0.5 or 25.0.13 (the versions released for the August security advisory), these issues are already fixed and no further action is needed.
Recommended Action:
-
Check your version. In the PaperCut admin console, go to About and note the version number.
-
Upgrade PaperCut NG/MF. If you're below the fixed version, upgrade to 26.0.5 (or 25.0.13 on the 25.x branch) or later.
-
Review administrator access. Two of these flaws need an attacker who already has PaperCut admin access. Make sure admin accounts use strong, unique passwords and that the admin interface can't be reached from the internet.
-
Hive customers with Ricoh devices only: update the PaperCut Hive embedded app to version 2.3.0 or later. It can be updated with a one-click install.
These vulnerabilities haven't been exploited, but one of them can be triggered without logging in. Keeping PaperCut up to date closes it off before anyone tries.
At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com
