Office multifunction printers have a flaw that lets internal device data be read out.
JPCERT/CC published it as JVNVU#90160989 on 30 September 2026, and Fujifilm Business Innovation and Sharp both issued advisories the same day. The identifier is CVE-2026-78249 and the class is path traversal (CWE-22).
JVN notes that the range of affected devices is wide.
What to do now
- ✓Identify your MFP model. For Sharp, anything other than the BP-1360M or BP-1250M is outside this advisory. For Fujifilm, find your model in the 28-row list below
- ✓If it is listed, read the fixed version on that row.
Do not memorise "1.50.6"; nine series number their firmware differently - ✓With Fujifilm EP-BB automatic update enabled, the update applies itself once released. Without it, contact the customer contact centre
- ✓For Sharp, ask your service representative for the patched firmware, as the advisory instructs
- ✓★On Sharp devices, do not rule yourself out from the version number alone. Sharp’s two official pages give different affected-version boundaries (below), so confirm with your service representative
- ✓★If you cannot update immediately, apply the workarounds both vendors publish. They centre on the administrator password. Change it from the default, make it long and complex, share it with as few people as possible, and change it promptly if you suspect it is widely known
- ✓Do not connect the MFP straight to the internet. Put it behind a firewall or router, and if outside access is required, restrict it to the necessary IP addresses or use a VPN (Fujifilm’s guidance)
Read the prerequisite before reacting: the attacker has to be able to log in to the management interface.
JVN puts it this way: "if an attacker able to log in to the product’s web management interface has a crafted request processed, important information inside the device may be stolen."
The CVSS vector reads PR:H, high privileges required. So this assumes someone who can get in as an administrator; it is not something anyone can fire from outside. Which is why the response centres on firmware updates and the administrator password.
The affected range differs sharply between the two vendors
Mixing these up means either needless panic or a missed device.
Sharp’s advisory covers "some of our digital multifunction devices manufactured for North America", and lists exactly two models, the BP-1360M and the BP-1250M. A Sharp device sold for the Japanese market is not in that advisory.
Fujifilm’s product list, by contrast, runs to 28 rows spanning Apeos, ApeosPrint, ApeosPro and Revoria Press. For those you have to find your model in the table.
Fujifilm reported this to JPCERT/CC, which then coordinated with both companies. Sharp’s advisory states that its CVSS v4.0 score is based on Fujifilm’s assessment. That is why one identifier covers two vendors’ products.
Fujifilm credits the discovery and report to Jim Rush of Tier Zero Security.
Sharp: two models and how to read the version
- ▸Affected: BP-1360M and BP-1250M (North America)
- ▸★Sharp’s Japanese advisory and its global support page state different affected versions.
The Japanese page says System version 25.11.27 and earlier; the global page says System version: All versions prior to 26.01.16.
The Controller version agrees: "1.0.3 and earlier" and "All versions prior to 1.0.4". - ▸To check the version: on the operation panel, press the gear icon at the left of the home screen, then Device Status, Details, Software Version
- ▸Fix: patched firmware exists. Sharp says to "ask your service representative for details"
★This gap changes what a reader concludes, so here it is plainly.
The two statements do not describe the same range. Going by the Japanese page alone, versions after 25.11.27 but before 26.01.16 look unaffected. By the global page they are affected.
I cannot tell which is correct. So if you are in that band, do not rule yourself out; ask your service representative. Assuming the wider range is the safe side.
The pages also name the products differently, "digital multifunction devices" versus "SHARP Press Series Monochrome Printing Systems", but the models are the same BP-1360M and BP-1250M in both.
Sharp lists three conditions for a successful attack, quoted:
1. the attacker can reach the corporate network the MFP is connected to; 2. the attacker holds administrator privileges; 3. the attacker has information not obtainable through normal operation.
It is written as needing all three together.
Fujifilm: affected products and fixed versions
This reproduces Fujifilm’s affected-product list. It runs to 28 rows, so start with the nine series whose fix is not 1.50.6. If your model is not among them, your fixed version is 1.50.6.
Seven products carry a mark in the advisory’s remarks column, meaning Fujifilm asks you to contact your sales representative. That is noted on each row.
Affected-product list: 28 rows
Fixed at 1.50.6 or later ......... 19 rows
Fixed at a different number ...... 9 series
of which: ask sales rep .......... 7 rows (marked *1)The nine series whose fix is not 1.50.6
- ▸Apeos 3061 / 2561 / 2061: 1.0.3 and earlier → 1.0.4 and later
- ▸Apeos C3061 / C2561 / C2061: 1.1.103 and earlier → 1.2.0 and later
- ▸Apeos C3567 / C3067 / C2567: 1.1.3 and earlier → 1.2.0 and later
- ▸Apeos C7071 / C6571 / C5571 / C4571 / C3571 / C3071 / C2571: 1.1.3 and earlier → 1.2.0 and later
- ▸ApeosPrint C3560 S / C3060 S: 1.20.105 and earlier → 1.20.10 and later
- ▸Revoria Press EC1100: 1.22.11 and earlier → 1.22.12 and later (marked *1 in the advisory: ask your sales representative)
- ▸Revoria Press EC2100S / EC2100: 1.1.4 and earlier → 1.3.0 and later (marked *1 in the advisory: ask your sales representative)
- ▸Revoria Press SC285S / SC285: 1.1.0 and earlier → 1.2.0 and later (marked *1 in the advisory: ask your sales representative)
- ▸RevoriaPress SC180 / SC170: 1.23.6 and earlier → 1.23.7 and later (marked *1 in the advisory: ask your sales representative)
The 19 rows fixed at 1.50.6 or later
- ▸Apeos 3060 / 2560 / 1860: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos 4570 / 3570: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos 5330: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos 6340: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos 7580 / 6580 / 5580: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos C2360 / C2060: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos C4030/C3530: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos C5240: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 / C2570: 1.50.5 and earlier → 1.50.6 and later
- ▸Apeos C8180 / C7580 / C6580: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint 4560 S / 3960 S / 3360 S: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint 4830 / 4830 JM: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint 6340: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint C4030 / C3530: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint C5240: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPrint C5570 / C4570: 1.50.5 and earlier → 1.50.6 and later
- ▸ApeosPro C810 / C750 / C650: 1.50.5 and earlier → 1.50.6 and later (marked *1 in the advisory: ask your sales representative)
- ▸Revoria Press E1136 / E1125/ E1110 / E1100: 1.50.5 and earlier → 1.50.6 and later (marked *1 in the advisory: ask your sales representative)
- ▸Revoria Press E1136P/E1125P/E1110P: 1.50.5 and earlier → 1.50.6 and later (marked *1 in the advisory: ask your sales representative)
Most rows read "1.50.5 and earlier, fixed in 1.50.6", but nine series number their firmware differently.
Remember it as "just go to 1.50.6" and you will mis-handle the Apeos 3061 series (1.0.4) or the Apeos C3061 series (1.2.0). Find your own row.
★Fujifilm splits its guidance by whether automatic updating is enabled.
With EP-BB automatic update configured, the device updates itself once the firmware is released. Without it, the advisory directs you to the customer contact centre.
Fujifilm also states that as of the notice, no attack exploiting this has been observed.
The ApeosPrint C3560 S / C3060 S row needs care
One row reads as though the numbers run backwards.
Affected is "1.20.105 and earlier" and fixed is "1.20.10 and later".
Compare the final segment as an integer and 10 is smaller than 105, so the fixed version looks older than the affected one.
I cannot tell whether that is a typo. How the version segments are meant to be compared, and therefore whether 1.20.105 or 1.20.10 is newer, is not something the advisory table settles.
If you run either of those two models, do not decide from the table alone; ask Fujifilm. The other 27 rows read straightforwardly, so this is the only row that trips.
JVN and the vendors disagree on the CVSS v4.0 attack vector
For the same CVE, the v4.0 vectors differ by one character. Here is what the sources say.
- ▸JVN: `CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N`, base score 6.9
- ▸Sharp and Fujifilm: identical from `AV:A` onwards, base score 6.8
- ▸All three give CVSS v3.1 as `AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N`, 4.9
The only difference is the v4.0 attack vector: JVN says `AV:N`, network, while both vendors say `AV:A`, adjacent network.
`AV:A` means the attacker has to be on the same network segment, which lines up with Sharp’s first condition, reaching the corporate network the MFP sits on. `AV:N` takes a broader view of reachability.
This article displays JVN’s v4.0 6.9. The vendors’ 6.8 is given alongside it so it is clear the higher figure was not taken silently. Both fall in MEDIUM, so the conclusion does not change.
Searching for the CVE returns nothing yet (as of 30 September 2026)
CVE-2026-78249 has no NVD page yet.
Querying the CVE ID service at CVE.org shows it RESERVED, and the NVD API returns zero results.
That does not mean the identifier is fake. Today the primary sources are JVN and the two vendor advisories. Do not read the absence from NVD as a reason to wait.
Three lines to pass on
- ▸Fujifilm and Sharp multifunction printers have a path traversal flaw (CVE-2026-78249). It needs a login to the management interface and exposes data inside the device
- ▸Sharp lists only the North America BP-1360M and BP-1250M. Fujifilm lists 28 rows across Apeos and others, and the fixed version differs by row (most are 1.50.6)
- ▸★If you cannot update yet, change the administrator password from its default and narrow who knows it. Do not expose the MFP directly to the internet
Sources
- JVNVU#90160989: path traversal in Fujifilm Business Innovation and Sharp multifunction printers (published 30 September 2026; CVSS and impact)↗
- Sharp advisory: vulnerability in our digital multifunction devices for North America (two models, version check, the three attack conditions, workarounds)↗
- Sharp global support page (detailed remediation steps)↗
- Fujifilm Business Innovation: path traversal vulnerability in our multifunction printers and printers (product list and fixed versions, workarounds, EP-BB automatic update)↗
- CVE.org: CVE-2026-78249 (RESERVED as of 30 September 2026)↗
