Ricoh Printers and MFPs Can Be Used as a Stepping Stone Into Your Network (CVE-2026-63226) β Update the Firmware if SSH Is On
A flaw in Ricoh printers and multifunction machines could let attackers use them as a passageway into a company's internal network. Only devices with the SSH remote-maintenance connection enabled are affected; if ignored, attacks can be relayed to other PCs and servers. Severity is medium, no exploitation has been reported, and updating the firmware fixes it.
Table of contents
A flaw in Ricoh printers and multifunction machines could let attackers use them as a passageway into a company's internal network. Only devices with the SSH remote-maintenance connection enabled are affected; if ignored, attacks can be relayed to other PCs and servers. Severity is medium, no exploitation has been reported, and updating the firmware fixes it.
A weakness has been found in Ricoh printers and multifunction printers (MFPs β the office machines that combine copying, scanning and faxing) that could be abused as a "passageway" into a company's internal network. It was published on July 23, 2026 in Japan's public vulnerability database JVN (JVN#32082029) and assigned the tracking ID "CVE-2026-63226."
Here is the bottom line first. The severity is "medium," and so far there are no reports of it being exploited. It only affects devices that have the special remote-maintenance connection called SSH turned on. Most home printers, and machines left on their default settings, are simply not affected. That said, MFPs managed in bulk by a company's IT department sometimes have this turned on, so it is worth calmly checking the conditions and the fix.
What actually happened with Ricoh printers and MFPs
The problem lies in a connection feature called "SSH" built into Ricoh printers and MFPs. SSH is a way to operate and maintain a device safely from a remote location, mainly used by IT administrators for configuration changes and maintenance.
SSH includes a feature called "port forwarding" that turns the connected device into a relay point to reach another machine. The weakness found this time is a design flaw where that forwarding destination is not restricted at all. Because the destinations that should be limited to only the necessary parties are left wide open, an attacker can use the MFP as a stepping stone to send traffic to other PCs and servers deep inside the corporate network.
The flaw was discovered by Brandon Roach and Bryan Clements of the U.S. security firm Pathfynder.io. In response, Ricoh has prepared fixed firmware (the base software that runs the device) that properly restricts the forwarding destination. Ricoh's official advisory (ricoh-2026-000006) lists the affected models and how to update.
Overview of the flaw (CVE-2026-63226)
Here are the key points at a glance.
| Item | Detail |
|---|---|
| Tracking ID | CVE-2026-63226 (JVN#32082029) |
| Affected | Ricoh printers and MFPs with the SSH feature |
| Type of flaw | Forwarding destination not restricted (CWE-923) |
| Severity | Medium (CVSS v4.0: 6.9 / v3.0: 5.8) |
| What could happen | The device is used as a stepping stone to relay traffic to other PCs and servers |
| Condition | Only when SSH is enabled |
| Exploitation | None reported so far |
| Fix | Update firmware to the latest version |
| Published | July 23, 2026 |
Severity is scored on a global yardstick called CVSS: 6.9 out of 10 on the latest version (v4.0) and 5.8 on the previous version (v3.0). The closer to 10, the more serious β and both land in the "medium" band. This is not the top-tier severity of a flaw that lets someone hijack the device outright with no conditions.
Who would target this, and why
The person who would exploit this is an attacker who has already gained a foothold somewhere inside the corporate network. Picture someone who slipped in through a malicious email attachment or a hole in another device, but who cannot yet reach the deeper server that holds the data they want. This is not a flaw that lets someone hijack an MFP straight from the internet.
When that attacker finds an MFP with SSH enabled, they use the device as a passageway to push traffic to internal servers and PCs they should not be able to reach directly. MFPs are often overlooked as "safe" equipment and are less closely monitored, which makes them a convenient relay point for moving deeper while staying hidden.
What lies ahead is what is called "lateral movement." If the attacker walks sideways across the internal network and reaches core servers or file servers, the MFP becomes the launch point for stealing confidential data or planting ransomware β the kind of virus that freezes operations to demand a ransom. The heart of this issue is not that the MFP itself breaks, but that the MFP becomes the entrance that puts the whole company at risk. As of now, there is no record of this flaw being added to the U.S. CISA "list of vulnerabilities under active attack" (you can check the latest status on the CISA KEV dashboard).
What is an "SSH passageway" (port forwarding) anyway?
Let us break the mechanism down a little more. SSH "port forwarding" is a relay feature that lets you communicate with another party by way of a device you have connected to. For example, you might legitimately connect from home to a company's SSH device and use that device as a turning point to reach a system that only works inside the office. For an IT administrator, it is a handy feature.
This feature is meant to have a restriction that narrows down "where forwarding is allowed." On the Ricoh devices in question, however, that restriction was not implemented. In classification terms, it falls under CWE-923, meaning the communication channel is not properly limited to its intended endpoints.
As a result, whoever reaches the MFP's SSH can use that MFP as a turning point to throw traffic almost anywhere on the internal network. A close analogy: separate from the front-door lock (logging into the device itself), the hallway leading from the entrance to the back rooms was left wide open.
What it looks like from a technical angle
The CVSS v3.0 breakdown captures the character of this flaw well. The vector is "AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N." It works over the network (AV:N), without special effort (AC:L), and with no user interaction (UI:N), while causing almost no direct destruction of the device's own confidentiality, integrity or availability (I:N / A:N).
The part worth noting is "S:C (scope change)." This means the impact spreads beyond the flawed device itself to a "different area of control" by using that device as a foothold. The MFP does not break, yet other machines on the internal network are put at risk through it β this port-forwarding abuse is a textbook case of that "scope change." It stays in the medium band because it is not a flaw that strips out data on its own; it is a "relay" that connects to a separate attack.
Printers and MFPs tend to be dismissed as "just peripherals," but they are in fact full-fledged computers connected to the network. Serious flaws that allow remote code execution have been reported again and again on MFPs from Ricoh and other makers. Office equipment needs to be managed as an update target, exactly like PCs and servers. Detailed technical information is also available on Ricoh's global security advisory list and the official CVE record.
Is your device affected?
First, stay calm and check in this order. The dividing line is "whether SSH is enabled."
- Home or SOHO use, running as purchased or on default settings β SSH is normally off, so you are most likely not affected.
- Individual or small office that has never touched the SSH settings β almost certainly not affected. If worried, just review the fixes below.
- A company IT department running multiple units in bulk with SSH enabled for remote maintenance β you may be affected. Check this as a priority.
The exact list of affected models and firmware versions differs by model. Ricoh's official advisory page lists the affected models and the fixed firmware, so match it against your model number. You can find the model number on the front of the unit, the settings screen, or the management console.
What to do right now
The response is simple. Work through the following from the top.
- Update the firmware to the latest version. Ricoh provides a fixed release that restricts the forwarding destination. This is the fundamental fix.
- If you cannot update right away, disable SSH if you are not using it. If you do not rely on it for remote maintenance, simply turning it off for now closes this path.
- Separate the MFP from the business network (network segmentation). Place the device in an isolated segment so it cannot freely talk to the outside or to critical servers, limiting the damage if something goes wrong.
- Do not leave SSH login credentials at their defaults. Change them to something hard to guess, and limit who can access the device to only those who need it.
If you manage many MFPs at a company, the fastest path is to start by taking inventory of "which devices have SSH enabled." Identify the enabled units and prioritize your updates from there.
Handle it calmly and there is nothing to fear
To recap: CVE-2026-63226 is a "medium" severity flaw that requires "SSH enabled" as a precondition. It is not the kind of thing that lets anyone hijack any MFP straight from the internet. There are no reports of exploitation so far, and Ricoh already has fixed firmware ready. There is no need to panic.
At the same time, do not put off action just because "an MFP is only a peripheral." Any device on the network can become a foothold for an attacker to move deeper. The most practical lesson from this case is to fold office equipment into your inventory as something to update and protect, just like PCs. First, check whether SSH is enabled on your device, and if it is, move the firmware to the latest version. That closes this particular hole.
Frequently asked questions
Q. Is the Ricoh printer I use at home dangerous too?
A. A home printer used as purchased or on default settings normally has remote-maintenance SSH turned off, so it is most likely not affected. Even if you are worried, keeping the firmware up to date is enough for peace of mind.
Q. Can this flaw be used to steal data inside the MFP?
A. This flaw does not break the MFP itself or pull data directly out of it. It is the type that uses the MFP as a "passageway" to relay traffic to other machines inside the company. What gets targeted are the servers and PCs beyond the MFP.
Q. I cannot update the firmware right away. What should I do?
A. If you do not rely on SSH for remote maintenance, simply disabling the SSH feature for now closes this path. It also helps to keep the MFP off the same network as critical servers and to change credentials from their defaults.
Q. Are there any reports of it already being attacked?
A. As of the July 23, 2026 disclosure, there are no confirmed reports of this flaw being exploited, nor any listing on the U.S. CISA "list of vulnerabilities under active attack (KEV)." Since the situation can change right after disclosure, updating early is the safe choice.
Sources
- βΈ JVN#32082029 - Access control issue in the SSH feature of Ricoh printers and MFPs (July 23, 2026)
- βΈ Ricoh - Security advisory (ricoh-2026-000006)
- βΈ Ricoh - Security Information List by Vulnerability (global)
- βΈ Official CVE record - CVE-2026-63226
- βΈ CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints
- βΈ Pathfynder - Brandon Roach (reporter)
- βΈ FIRST - CVSS v4.0 calculator (score breakdown for this case)

Makoto Horikawa
Backend Engineer / AWS / Django