PaperCut NG/MF Sep 2026 bulletin: CVE-2026-14780/82077 auth RCE + CVE-2026-87739 unauth report bypass; Hive Ricoh CVE-2026-11744
PaperCut Security Bulletin (24 September 2026 AEST; vulnerability log updated same day) discloses four issues fixed in current maintenance trains. PaperCut NG/MF: CVE-2026-14780 (CVSS 4.0 7.5 HIGH) — authenticated administrator RCE via optional Print/Device Scripting (disabled by default since 22.1.1; fixed earlier in 26.0.2 / 25.0.12); CVE-2026-82077 (CVSS 4.0 7.3 HIGH, watchTowr) — authenticated admin path-traversal/command injection in Scan-to-Fax; CVE-2026-87739 (CVSS 4.0 6.9 MEDIUM, internal) — unauthenticated remote attacker can trigger report generation and obtain sensitive report data (CWE-639). PaperCut Hive Embedded Application for Ricoh: CVE-2026-11744 (CVSS 4.0 3.8 LOW) — local NFC-card XSS into the embedded webview sandbox. Vendor note: sites already on NG/MF 26.0.5 or 25.0.13 already have the NG/MF fixes; Hive Ricoh app → 2.3.0. Distinct from desk papercut-ng-mf-20260827 (Aug active-exploitation EPR / CVE-2026-82078/81578 wave) though patch floors overlap. Primary: PaperCut bulletin.
- Product
- PaperCut NG/MF; PaperCut Hive Embedded Application for Ricoh
- Versions
- NG/MF: fixed in 26.0.5 and 25.0.13 (14780 also fixed in 26.0.2 / 25.0.12). Hive Ricoh embedded app: fixed in 2.3.0. Older NG/MF trains before those floors remain exposed for the listed CVEs.
- CVSS
- / 7.3 / 6.9 / 3.8 (CVSS 4.0 vendor: 14780 HIGH, 82077 HIGH, 87739 MEDIUM, 11744 LOW)
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N (14780); CVSS:4.0 - Exploited in Australia?
- unknown
- Patch to
- Upgrade PaperCut NG/MF to 26.0.5 (or 25.0.13 on 25.x) or later; upgrade Hive Embedded Ricoh app to 2.3.0; keep Application Server off the public internet; review scripting/Scan2Fax/report-generation exposure for admin and unauthenticated paths
Primary: PaperCut — NG/MF Security Bulletin (24 Sep 2026) · Vendor: PaperCut vendor security bulletin (Sep 2026) · CVE: CVE-2026-14780, CVE-2026-87739, CVE-2026-11744, CVE-2026-82077, CVE-2026-82078 · PaperCut — Security vulnerability log (updated 24 Sep 2026)
