# CERT-FR flags multiple PaperCut vulnerabilities

Published: 2026-09-24 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/7911c0b6-6341-5fa8-9616-fc298873bb5a/cert-fr-flags-multiple-papercut-vulnerabilities

> CERT-FR advisory details PaperCut NG/MF and Hive Embedded flaws allowing RCE, data exposure, and XSS; patches available.

CERT-FR published an advisory covering multiple vulnerabilities in PaperCut print management software, affecting PaperCut Hive Embedded Application versions prior to 2.3.0 (Ricoh), and PaperCut NG/MF versions 25.x before 25.0.13 and 26.x before 26.0.5. The vulnerabilities allow an attacker to achieve remote arbitrary code execution, breach data confidentiality, bypass security policies, and conduct indirect remote code injection (XSS).

Four CVEs are referenced (CVE-2026-11744, CVE-2026-14780, CVE-2026-82077, CVE-2026-87739) tied to the vendor's September 2026 security bulletin, though the advisory does not provide per-CVE technical descriptions. No evidence of active exploitation in the wild is mentioned in the bulletin. Defenders running affected PaperCut deployments, including Ricoh-embedded Hive instances, should apply vendor patches referenced in the official PaperCut security bulletin without delay, given PaperCut's history of being targeted by ransomware actors following prior vulnerability disclosures.

Organizations should prioritize patching print management infrastructure, verify version levels against the fixed releases listed, and monitor for anomalous authentication or code execution activity on PaperCut servers as a precaution.

## Mentioned in this report

- Vulnerabilities: CVE-2026-11744, CVE-2026-14780, CVE-2026-82077, CVE-2026-87739

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1223

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7911c0b6-6341-5fa8-9616-fc298873bb5a/cert-fr-flags-multiple-papercut-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
