VORANT. Threat Intelligence Sign in Create a free account

CERT-FR flags multiple PaperCut vulnerabilities

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory details PaperCut NG/MF and Hive Embedded flaws allowing RCE, data exposure, and XSS; patches available.

CERT-FR published an advisory covering multiple vulnerabilities in PaperCut print management software, affecting PaperCut Hive Embedded Application versions prior to 2.3.0 (Ricoh), and PaperCut NG/MF versions 25.x before 25.0.13 and 26.x before 26.0.5. The vulnerabilities allow an attacker to achieve remote arbitrary code execution, breach data confidentiality, bypass security policies, and conduct indirect remote code injection (XSS).

Four CVEs are referenced (CVE-2026-11744, CVE-2026-14780, CVE-2026-82077, CVE-2026-87739) tied to the vendor's September 2026 security bulletin, though the advisory does not provide per-CVE technical descriptions. No evidence of active exploitation in the wild is mentioned in the bulletin. Defenders running affected PaperCut deployments, including Ricoh-embedded Hive instances, should apply vendor patches referenced in the official PaperCut security bulletin without delay, given PaperCut's history of being targeted by ransomware actors following prior vulnerability disclosures.

Organizations should prioritize patching print management infrastructure, verify version levels against the fixed releases listed, and monitor for anomalous authentication or code execution activity on PaperCut servers as a precaution.

Mentioned in this report

Vulnerabilities CVE-2026-11744CVE-2026-14780CVE-2026-82077CVE-2026-87739

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1223

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,789 reports from 155 sources, 1,534 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs