đź”’ Client Login Order Supplies Submit Meter Read Request Service Get a Quote

PaperCut September Bulletin: 4 Security Fixes to Verify

PaperCut September bulletin security update for print systems

The PaperCut September bulletin disclosed four vulnerabilities affecting PaperCut NG/MF and the PaperCut Hive Embedded Application for Ricoh. PaperCut says it has no evidence that these issues have been exploited, but customers should still confirm their installed versions and plan the appropriate update. For PaperCut NG/MF, the current fixes are version 26.0.5 or version 25.0.13 on the 25.x branch. The affected Ricoh embedded application is fixed in version 2.3.0.

The PaperCut September bulletin is not the same as PaperCut’s urgent August 27 advisory about confirmed exploitation. The maintenance releases published September 10 include the August fixes and also contain fixes discussed in the newer bulletin. The practical task is to verify which PaperCut products and components your organization actually uses, confirm the installed versions, and test the upgrade without disrupting printing, authentication, scanning, or reporting.

What did the PaperCut September bulletin disclose?

PaperCut’s official September 24 security bulletin describes four CVEs with different prerequisites and impacts:

  • CVE-2026-14780 — Print and Device Scripting remote code execution. An attacker who already has authenticated administrator access could run code on the PaperCut application server when the optional scripting feature is enabled. PaperCut says scripting has been disabled by default since version 22.1.1. This issue was fixed in 26.0.2 and 25.0.12.
  • CVE-2026-82077 — Scan2Fax remote code execution. An authenticated PaperCut administrator could use crafted fax-provider settings to execute commands on the application server. The fix is included in 26.0.5 and 25.0.13.
  • CVE-2026-87739 — unauthorized report generation. This issue can allow an unauthenticated remote attacker to trigger report generation and gain access to sensitive information. The fix is included in 26.0.5 and 25.0.13.
  • CVE-2026-11744 — Ricoh Hive embedded-app JavaScript injection. A person with physical access to the device and a specially crafted NFC card or emulator could exploit the embedded application. PaperCut identifies version 2.3.0 as the fixed Ricoh app release.

The details matter. Two issues require existing PaperCut administrator access, one is remotely reachable without authentication, and one requires physical access to a Ricoh device. A single statement such as “the server is not internet-facing” does not answer every exposure question.

Which PaperCut versions should you verify?

The PaperCut September bulletin recommends PaperCut NG/MF 26.0.5, or 25.0.13 for organizations remaining on the 25.x branch. Those releases were published September 10, 2026. PaperCut’s security vulnerability log also lists those versions for the NG/MF issues and version 2.3.0 for the PaperCut Hive Embedded Application for Ricoh.

Do not assume that the words “version 25,” “version 26,” or “latest patch” are specific enough. Record the complete version and build shown in the administration interface. Also identify optional components, embedded applications, site servers, database integrations, and custom scripts that may affect the upgrade plan.

If your organization is on version 24 or an older release, do not assume that the September 10 release for that branch resolves the four issues disclosed September 24. Ask PaperCut or your authorized provider for the supported upgrade path that applies to your installation and maintenance status.

How is this different from the August emergency advisory?

PaperCut’s August 27 advisory addressed a separate situation involving confirmed customer incidents and active exploitation. PaperCut later released 26.0.5, 25.0.13, and 24.1.10 to replace the emergency patches associated with that advisory.

The PaperCut September bulletin says PaperCut has no evidence that its four newly disclosed issues have been exploited. That difference affects the context, but it is not a reason to ignore the new disclosure. The same maintenance releases may address more than one advisory, so a good change record should identify the exact version installed and the bulletins that version resolves.

If the environment may have been exposed during the August incident, patching alone is not an investigation. Preserve the earlier advisory, indicators of compromise, and response guidance for the security team or qualified incident-response provider.

A practical PaperCut security update checklist

1. Identify the owner

Determine who is responsible for the PaperCut application server, embedded applications, operating system, database, backups, and firewall exposure. Responsibilities may be divided among internal IT, a managed IT provider, an equipment dealer, and a PaperCut reseller. Do not assume a copier service agreement includes application-server patching unless the written scope says so.

2. Inventory the installed components

Record the NG or MF version, operating system, database, site servers, Print Deploy components, embedded applications, and any use of Print and Device Scripting or Scan2Fax. For Ricoh devices using PaperCut Hive, record the embedded-app version separately.

3. Compare versions with the official bulletin

Use the current PaperCut bulletin rather than a screenshot, social post, or copied advisory. Confirm whether each component is affected and which release resolves it. If the provider recommends a different path, ask for the reason and the supporting PaperCut documentation.

4. Review exposure and privileged access

Confirm whether PaperCut web interfaces are reachable from untrusted networks, which accounts have administrative access, and whether those accounts use strong authentication. Review recent administrative changes and report activity appropriate to your environment. Restricting exposure and privileged access remains useful even after patching.

5. Prepare a controlled change

Review release notes, compatibility requirements, maintenance status, current backups, custom integrations, and rollback options. Schedule the work around business operations. An update to the PaperCut application server and an update to a device’s embedded application are different changes and may need separate testing.

6. Test the workflows people depend on

After the update, test user authentication, secure release, desktop printing, mobile or guest workflows, scanning, Scan2Fax if used, reporting, accounting codes, card readers, and device-panel behavior. Include more than one site or device model when the fleet is mixed.

7. Document the result

Record the old and new versions, date, person or provider responsible, affected systems, tests performed, exceptions, and follow-up work. Keep the official bulletin with the change record so the organization can show what it verified.

What should you ask your managed print or IT provider?

Use the PaperCut September bulletin to ask direct questions that produce a verifiable answer:

  • Which PaperCut products and versions do we run today?
  • Are we affected by any of the four September 24 CVEs?
  • Who owns the application-server and embedded-app updates under our agreement?
  • Which target versions will be installed?
  • Are any custom scripts, Scan2Fax settings, card readers, or embedded applications affected?
  • How will you back up, test, and document the change?
  • Does the environment require separate review because of the August 27 incident?

A provider should be able to distinguish “the update is available,” “the update is scheduled,” and “the update was installed and tested.” Those are three different states.

What this means for Tallahassee and North Florida organizations

Law firms, medical offices, public agencies, schools, and other organizations often rely on PaperCut for secure release, reporting, and scanning. Those workflows can involve confidential or regulated information, but the security decision should still be based on the actual architecture and documented responsibilities—not on the industry label alone.

Advanced Business Systems supports office technology and managed print environments across Tallahassee, North Florida, Thomasville, and South Georgia. If you do not know who owns your PaperCut update process, ABS can help inventory the environment, identify the responsible parties, and coordinate a controlled review. The applicable service scope and any project cost should be confirmed in writing before work begins.

Frequently asked questions

Is the September 24 PaperCut bulletin being actively exploited?

The PaperCut September bulletin stated on September 24, 2026 that PaperCut had no evidence these four issues had been exploited. That statement is specific to this bulletin and can change. PaperCut’s separate August 27 advisory did involve confirmed incidents, so do not combine the two risk statements.

Does version 25.0.13 fix the NG/MF issues?

Yes, PaperCut identifies 25.0.13 as the fixed release for customers on the 25.x branch. Version 26.0.5 is the corresponding recommendation on the 26.x branch. Verify the complete installed version rather than relying on the major version alone.

Do Ricoh devices need a separate update?

The Ricoh issue affects the PaperCut Hive Embedded Application and is fixed in version 2.3.0. That is separate from upgrading a PaperCut NG/MF application server. Confirm which PaperCut product and embedded app the device actually uses.

Must every printer be shut down during the server update?

Not necessarily, but users may lose PaperCut-dependent functions while server or embedded components are being updated. The effect depends on the design. Plan the window, communicate the expected interruption, and test critical workflows afterward.

Where should we verify the latest information?

Use the official PaperCut September bulletin, vulnerability log, release history, and upgrade documentation. Recheck those sources immediately before making a production change because advisories can be revised.

Related resources from ABS

Scroll to Top