-
Help Center home
-
Product manuals
-
Release notes
-
System requirements
Security vulnerability log
Last updated September 24, 2026
This page displays information about specific security vulnerabilities.
Security vulnerability log
Ordered from newest to oldest.
|
Name & date |
Vulnerability ID(s) |
Details |
|
PaperCut NG/MF and PaperCut Hive Embedded App for Ricoh Security vulnerabilities 24 September 2026 |
CVE-2026-14780 CVE-2026-11744 |
Resolved in PaperCut NG/MF version 26.0.5 Addressed three vulnerabilities: two High-severity authenticated Remote Code Execution (RCE) flaws in the Scripting Subsystem (CVE-2026-14780) and Scan2Fax component (CVE-2026-82077), and one Medium-severity unauthenticated authorization bypass allowing unauthorized report generation (CVE-2026-87739). Resolved in PaperCut Hive Embedded App for Ricoh version 2.3.0 Addressed a Low-severity JS injection / XSS flaw (CVE-2026-11744) triggered via crafted NFC card input requiring physical access to the MFD. See PaperCut NG/MF Security Bulletin (September 2026) for more information. |
|
PaperCut NG/MF Security vulnerabilities |
CVE-2026-82078 |
Security advisory published on 27th August 2026 for immediate action. See URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) for more information. |
|
PaperCut NG/MF Security vulnerabilities |
CVE-2026-8793 |
Resolved in PaperCut NG/MF version 26.0.3. Resolved two authentication-related issues in the login component, insufficient brute-force protection and username enumeration via a timing discrepancy, that could allow an unauthenticated remote attacker to attempt password brute-force/credential-stuffing or enumerate valid usernames. See PaperCut NG/MF Security Bulletin (3 August 2026) for more information. |
|
Underscore.js August 2026 |
CVE-2026-27601 |
Resolved in PaperCut NG/MF version 26.0.3. We have determined that this vulnerability has minimal impact in PaperCut NG/MF. The affected _.flatten and _.isEqual functions run only in the client browser and are triggered only under specific conditions. While we ship a version of Underscore.js that includes the vulnerability (versions up to 1.13.7), the worst-case outcome is a page remaining in a loading state until the user reloads it, with no confidentiality or integrity impact. Internal reference [PO-4141] |
|
PaperCut NG/MF Security vulnerabilities |
CVE-2026-6645 |
Resolved in PaperCut Print Deploy Client v2699 (bundled with Print Deploy server version 1.10.4178). Resolved an insecure search path vulnerability in the Print Deploy Client for Windows that could allow a local attacker to execute code with SYSTEM privileges. |
|
PaperCut NG/MF and PaperCut Hive Security vulnerabilities |
CVE-2026-6418 |
Resolved security vulnerabilities including a path validation issue in Shared Account Synchronization, a diagnostic logging issue in the Ricoh embedded app, and a race condition in HP badge-swipe processing. |
|
PaperCut NG/MF security vulnerabilities |
CVE-2026-4794 |
Resolved in PaperCut NG/MF version 25.0.10. |
|
Apache Log4j Core Jan 2026 |
CVE-2025-68161 |
Resolved in PaperCut NG/MF version 25.0.10. We have determined that this is not reachable via PaperCut NG/MF. This is because our software does not use remote logging capabilities of the library, which must be used for the vulnerability to be reachable. While we're using a version of Apache Log4j Core that includes the vulnerability, PaperCut products are not exploitable to this vulnerability. Internal reference [PO-3935] |
|
Spring vulnerability Oct 2025 |
CVE-2025-41254 |
We have determined that this is not reachable via PaperCut NG/MF. This is because our software does not use Simple Messaging Protocol or STOMP, which must be used for the vulnerability to be reachable. While we're using a version of Spring Framework that includes this vulnerability, PaperCut products are not susceptible to this. Internal reference [PO-3567] |
|
Spring vulnerability Oct 2025 |
CVE-2025-41253 |
We have determined that this is not reachable via PaperCut NG/MF. This is because our software does not utilize Spring Webflux, which is the only affected component according to the Spring Security advisory. Internal reference [PO-3567] |
|
Spring vulnerability Sept 2025 |
CVE-2025-41249 |
We have determined that these are not reachable via PaperCut NG/MF. This is because our software does not use Internal reference [PO-3567] |
|
Spring Cloud Gateway Server Webflux vulnerability Sept 2025 |
CVE-2025-41243 |
Is PaperCut NG/MF impacted by CVE-2025-41243? |
|
PaperCut NG/MF security vulnerabilities |
CVE-2025-9785 |
Resolved an issue with documentation surrounding the configuration of Print Deploy SSL/TLS certificate validation prior to the release of Print Deploy version 1.9.2917 (prior to 7 July 2025). See PaperCut Print Deploy Security Bulletin (September 2025) for more information. |
|
PaperCut NG/MF security vulnerabilities |
CVE-2024-9672 |
Resolved in PaperCut NG/MF version 24.1.1. See PaperCut NG/MF Security Bulletin - Dec 2024 for more information. |
|
Ghostscript vulnerabilities Nov 2024 |
CVE-2024-46951 |
Resolved in Ghostscript 10.04.0 which is included in Ghost Trap 1.6.10.04.0. See Ghostscript vulnerabilities KB for more information. |
|
Spring vulnerability Oct 2024 |
CVE-2024-38821 |
We have determined that this is not reachable via PaperCut NG/MF. This is because our software does not utilize Spring Webflux, which is the only affected component according to the Spring Security advisory. Internal reference [PO-3567] |
|
CUPS vulnerabilities Sept 2024 |
CVE-2024-47076 |
PaperCut products do not make use of the See Ubuntu's CUPS Remote Code Execution Vulnerability Fix Available (via Canonical) or Red Hat’s response to OpenPrinting CUPS vulnerabilities for more information. Note that these vulnerabilities do not impact Microsoft Windows. |
|
Ghostscript vulnerabilities May 2024 |
CVE-2024-33869 |
Resolved in Ghostscript 10.03.1 which is included in Ghost Trap 1.4.10.03.1. See Ghostscript vulnerabilities KB for more information. |
|
PaperCut NG/MF security vulnerabilities Updated May 2025 |
CVE-2024-3037 |
Resolved in PaperCut NG/MF version 23.0.9. May 2025 Update: The fixed version and process for CVE-2024-8404 has changed. The CVE score remains unchanged. See PaperCut NG/MF Security Bulletin - May 2025 for more information |
|
Amazon Corretto Java dependencies |
Various CVEs |
Vulnerability scanners have flagged several CVEs which relate to a 3rd party dependency (Amazon Corretto Java) in PaperCut NG/MF. These have been remediated with the upgrade to Java version 11.0.22.7.1 included in PaperCut NG/MF version 23.0.8. |
|
Ghostscript vulnerability in calling the Tesseract library |
N/A |
A vulnerability was identified in the way Ghostscript/GhostPDL called tesseract for the OCR devices. See the Ghostscript site for more information. |
|
PaperCut NG/MF security vulnerabilities |
CVE-2024-1222 |
There is an update now available for PaperCut NG/MF customers. Versions 23.0.7, 22.1.5, 21.2.14, 20.1.10 have now been released with fixes for these vulnerabilities. |
|
Spring Framework URL Parsing with Host Validation |
CVE-2024-22243 |
Resolved in PaperCut NG/MF version 24.0.3 Our internal teams have investigated this issue and have found that PaperCut NG/MF do use the version of Spring that is vulnerable to CVE-2024-22243. However, we are currently not aware of any known paths to exploit these vulnerabilities. |
|
Apache Struts file upload exploit |
CVE-2023-50164 |
Is PaperCut impacted by CVE-2023-50164? |
|
PaperCut NG/MF security vulnerability |
CVE-2023-6006 |
CVE-2023-6006 - Privilege escalation vulnerability |
|
curl/libcurl vulnerabilities |
CVE-2023-38545 |
Is PaperCut impacted by CVE-2023-38545, CVE-2023-38546 or CVE-2023-38039? |
|
Heap buffer overflow in libwebp |
CVE-2023-4863 |
Is PaperCut impacted by CVE-2023-4863? |
|
Unauthenticated XMLRPC Functionality |
CVE-2023-4568 |
PaperCut Software is aware of Tenable's view on CVE-2023-4568, impacting PaperCut MF and NG. PaperCut has different perspectives and assessments. We do however echo the advice for customers to review their Options -> Advanced -> Security -> Allowed remote provider IP addresses, and/or firewall settings, to ensure security is appropriate for a given install (as detailed in the IP Address Allow-listing section of the Secure setup page). |
|
GhostScript vulnerabilities |
CVE-2023-36664 |
Please see the GhostScript Vulnerabilities KB for more information. |
|
PaperCut Mobility Print security vulnerabilities |
CVE-2023-2508 |
CVE-2023-2508 - Address potential CSRF attack in Mobility Print |
|
PaperCut NG/MF security vulnerabilities |
CVE-2023-3486 |
CVE-2023-3486 - Potential Denial of Service Issue |
|
PaperCut NG/MF security vulnerabilities |
CVE-2023-31046 |
CVE-2023-31046 - Path traversal vulnerability |
|
SpEL expression DoS in Spring Framework |
CVE-2023-20863 |
The Spring framework is only used in PaperCut NG/MF. No other PaperCut products (including Multiverse, Mobility Print, Print Deploy, PaperCut Hive and Pocket) use Spring. There is limited product impact since SpEL expressions are used in a limited fashion within PaperCut NG/MF, and do not have direct user-input points. We aim to upgrade the Spring framework in use as part of our regular maintenance upgrades, in a future release of PaperCut MF and NG. |
|
Service Location Protocol (SLP) |
CVE-2023-29552 |
PaperCut products (including PaperCut NG/MF, Multiverse, Mobility Print, Print Deploy, PaperCut Hive and Pocket), do not use SLP functionality. Please check with your printer manufacturer or refer to your printer manufacturer online documentation regarding disabling the protocol. See CVE-2023-29552 for more information about the vulnerability. |
|
Spring double wildcard |
CVE-2023-20860 |
Is PaperCut impacted by the Spring double wildcard vulnerability CVE-2023-20860? |
|
PaperCut NG/MF security vulnerabilities |
CVE-2023-27350 |
We have received two vulnerability reports for a high severity and critical security issue in PaperCut NG/MF. |
|
XML external entity (XXE) injection vulnerability in XML-RPC.NET |
CVE-2022-47514 |
Is PaperCut impacted by CVE-2022-47514? |
|
OpenSSL Vulnerabilities |
CVE-2022-3602 |
Is PaperCut impacted by OpenSSL vulnerabilities? |
|
Text4Shell / TextShell |
CVE-2022-42889 |
Is PaperCut impacted by the Apache Commons Text vulnerability CVE-2022-42889? |
|
Psychic Signatures |
CVE-2022-21449 |
Is PaperCut impacted by the Java vulnerability CVE-2022-21449? |
|
PaperCut NG/MF security vulnerability |
PC-18750 |
We have received a vulnerability report for a high severity security issue in PaperCut NG/MF from version 19.2.1 through to the 21.2.8 release. |
|
SpringShell |
CVE-2022-22965 |
Is PaperCut impacted by SpringShell/Spring4Shell? |
|
Improper Restriction of XML External Entity |
CVE-2022-0839 |
Is PaperCut impacted by CVE-2022-0839? |
|
Ghost script vulnerabilities |
CVE-2019-14869 |
Is PaperCut impacted by vulnerabilities for Ghost script? |
|
Log4j 1.2 (SocketServer) |
CVE-2019-17571 |
Is PaperCut impacted by the Log4j 1.2 SocketServer vulnerability? |
|
Log4Shell (RCE in log4j) |
CVE-2021-44228 |
Is PaperCut impacted by the Apache log4j Remote Code Execution vulnerability? |
|
MS update KB5005408 (Smart card authentication) |
CVE-2021-33764 |
Is PaperCut impacted by the Microsoft update KB5005408 (Smart card authentication)? |
|
PrintNightmare |
CVE-2021-1675 |
Is PaperCut affected by the “Windows Print Spooler Elevation of Privilege Vulnerability” (otherwise known as CVE-2021-1675 or CVE-2021-34527)? |
|
Jasper reports directory traversal |
CVE-2018-18809 |
We are aware of customer systems flagging the version of Jasper reports used with PaperCut NG/MF as vulnerable. While CVE-2018-18809 relates to a subcomponent that PaperCut NG/MF doesn't actively utilize, we will be resolving this by updating Jasper reports in a future version. |
|
Freak |
CVE-2015-0204 |
Is PaperCut affected by the SSL/TLS “FREAK” attack (CVE-2015-0204)? |
|
Poodle |
CVE-2014-3566 |
Is PaperCut affected by the SSL 3.0 “Poodle” vulnerability (otherwise known as CVE-2014-3566)? |
|
Shellshock |
CVE-2014-6271 |
Is PaperCut impacted by the Shellshock vulnerability (CVE-2014-6271) and (CVE-2014-7169)? |
|
Heartbleed |
CVE-2014-0160 |
Is PaperCut affected by the OpenSSL “Heartbleed” vulnerability (otherwise known as CVE-2014-0160)? |
More on security at PaperCut
- Need to make sure you receive critical security notifications by email? Subscribe to security notifications.
- Looking for more information about security at PaperCut, and common questions about security? Check out our Common Security Questions page.
Category: Reference Articles
Subcategory: Security and Privacy
Comments
Comments are not available in this preview environment. On papercut.com, this space shows the live Disqus comment thread for this page.