Vulnerability
Published 2026-09-24
Verified 2026-09-27

PaperCut NG/MF Sep 2026 bulletin: CVE-2026-14780/82077 auth RCE + CVE-2026-87739 unauth report bypass; Hive Ricoh CVE-2026-11744

PaperCut Security Bulletin (24 September 2026 AEST; vulnerability log updated same day) discloses four issues fixed in current maintenance trains. PaperCut NG/MF: CVE-2026-14780 (CVSS 4.0 7.5 HIGH) — authenticated administrator RCE via optional Print/Device Scripting (disabled by default since 22.1.1; fixed earlier in 26.0.2 / 25.0.12); CVE-2026-82077 (CVSS 4.0 7.3 HIGH, watchTowr) — authenticated admin path-traversal/command injection in Scan-to-Fax; CVE-2026-87739 (CVSS 4.0 6.9 MEDIUM, internal) — unauthenticated remote attacker can trigger report generation and obtain sensitive report data (CWE-639). PaperCut Hive Embedded Application for Ricoh: CVE-2026-11744 (CVSS 4.0 3.8 LOW) — local NFC-card XSS into the embedded webview sandbox. Vendor note: sites already on NG/MF 26.0.5 or 25.0.13 already have the NG/MF fixes; Hive Ricoh app → 2.3.0. Distinct from desk papercut-ng-mf-20260827 (Aug active-exploitation EPR / CVE-2026-82078/81578 wave) though patch floors overlap. Primary: PaperCut bulletin.

Product
PaperCut NG/MF; PaperCut Hive Embedded Application for Ricoh
Versions
NG/MF: fixed in 26.0.5 and 25.0.13 (14780 also fixed in 26.0.2 / 25.0.12). Hive Ricoh embedded app: fixed in 2.3.0. Older NG/MF trains before those floors remain exposed for the listed CVEs.
CVSS
/ 7.3 / 6.9 / 3.8 (CVSS 4.0 vendor: 14780 HIGH, 82077 HIGH, 87739 MEDIUM, 11744 LOW)
Exploited in Australia?
unknown
Patch to
Upgrade PaperCut NG/MF to 26.0.5 (or 25.0.13 on 25.x) or later; upgrade Hive Embedded Ricoh app to 2.3.0; keep Application Server off the public internet; review scripting/Scan2Fax/report-generation exposure for admin and unauthenticated paths

Primary: PaperCut — NG/MF Security Bulletin (24 Sep 2026) · Vendor: PaperCut vendor security bulletin (Sep 2026) · CVE: CVE-2026-14780, CVE-2026-87739, CVE-2026-11744, CVE-2026-82077, CVE-2026-82078 · PaperCut — Security vulnerability log (updated 24 Sep 2026)

vulnerabilities australia