Top/Articles/Sharp printer flaw CVE-2026-60011 affects 164 models, 78 get no fix
sharp-toshibatec-mfp-cve-cover-en

Sharp printer flaw CVE-2026-60011 affects 164 models, 78 get no fix

A flaw in 164 Sharp multifunction printer models lets stored scans be read without logging in. 78 models are past firmware support and get no fix at all.

NewsPublished Aug. 3, 2026 Updated today
Table of contents
Key takeaways

A flaw in 164 Sharp multifunction printer models lets stored scans be read without logging in. 78 models are past firmware support and get no fix at all.

Sharp digital multifunction printers (the office machines that combine copying, printing and scanning) have a flaw that lets someone pull scanned document images out of the machine without ever passing its login screen. The identifier is CVE-2026-60011. Sharp published an official advisory on July 31, 2026, and the same day it appeared on JVN, the vulnerability portal run by Japan's national agencies.

What makes this one heavy is the scope. Counting the model names listed in Sharp's advisory gives 164 models. And of those, 78 models are marked as having reached end of firmware support, meaning no fix will be shipped for them. Machines that can be repaired and machines that cannot are sitting in the same document, split across Table 1 and Table 2.

On the same day, Sharp also disclosed a separate flaw in the scan-receiving software that runs on the PC side (CVE-2026-62416, JVNVU#92540957). Both the printer and the PC need attention.

ItemDetail
IdentifiersCVE-2026-60011
CVE-2026-63545
CVE-2026-63563
AffectedSharp digital MFPs
Toshiba Tec MFPs (North America)
Model count164 Sharp models
(78 with no fix available)
ImpactStored images read without login
Unrelated files printed via USB
Severity (CVSS)6.9 / 2.4 / 6.9
(CVSS v4.0, out of 10)
ExploitationNo reports of abuse
DisclosedJuly 31, 2026

Note: CVSS is an international scale that rates severity from 0 to 10. The figures above are the ones published by Sharp and JVN.

Three flaws, but only two matter for machines sold in Japan

JVN lists three identifiers, but only two of them apply to machines sold on the Japanese market. Getting this wrong means worrying about something that does not affect you.

CVE-2026-60011: Reading stored documents without logging in

This is the main one. Sharp describes it as an attacker being able to tamper with HTTP requests to the printer's web pages and reach image data stored on the machine while bypassing the web page authentication. In plain terms: the printer's settings screen is supposed to require an ID and password, but hitting a crafted address directly slips past that step and reaches the scanned images sitting in the machine. JVN summarizes the effect as retrieval of images the user has no permission to view.

CVE-2026-63545: Printing from USB brings out someone else's document

Sharp's wording is that attempting to print a crafted PDF from USB storage causes a different file stored inside the machine to be printed unexpectedly. Temporary files that should have been cleared after printing stay behind, and they can be coaxed back out. The severity is a low 2.4, but the result is someone else's paperwork physically coming out of the tray in front of you β€” a very easy kind of leak to picture.

CVE-2026-63563: Products for the Japanese market are not affected

This one reads as the scariest of the three: user authentication is disabled by default, so address book editing and document filing functions can be used with no login at all. But JVN states plainly that products intended for the Japanese domestic market are not affected. Consistent with that, this identifier does not appear anywhere in Sharp's Japanese advisory 2026-004, which covers only 60011 and 63545.

Toshiba Tec's notice published the same day lists six models β€” e-STUDIO 908 / 1058 / 1208 and e-STUDIO 907 / 1057 / 1207 β€” followed immediately by a line stating that these products are deployed in the North American market only. There is no sentence in Toshiba Tec's document explicitly saying that domestic models are out of scope; reading it as "these six models are themselves North American products" is the most faithful interpretation of the original.

Who goes after this, and what for

To be realistic about it, the person reaching for this flaw is someone who already has a foothold on that office network. An attacker who got into one workstation through a mail that looked like it came from a supplier, a visitor who managed to join the guest Wi-Fi, or β€” if the printer has been left reachable from the internet β€” anyone passing by. A multifunction printer looks like a machine that prints things, but inside it is a computer with a hard disk and a web server, permanently attached to the office network and watched by nobody.

What does such a person do with it? The use for this particular flaw is collecting the scanned images piled up inside the machine without logging in. Paper that goes through an office MFP tends to be contracts, quotes, medical check-up results, performance reviews, stamped application forms. Data that someone scanned and never came back for turns into a shelf that can be emptied.

The damage lands in two places. For the employees, customers and business partners named in those documents, there is no way to notice that their information moved. For the company, on top of the leak itself, the harder problem is being unable to establish when and how much was taken β€” almost no organization reviews its printer's audit logs as a matter of routine. That is exactly why the last item on Sharp's list of workarounds is to check the audit log periodically for traces of suspicious access.

Is the machine in your office affected

Sharp's advisory splits the models into Table 1, which will receive corrected firmware, and Table 2, which has reached end of support. Start by checking your printer's model number, printed on a label on the front of the unit or beside the control panel.

The table below covers the Table 1 groups. The numbers are the firmware versions at or below which the machine is affected; the advisory does not state the version numbers of the fixed firmware, which is handled through the dealer.

Model group (color)Affected firmware
BP-71C / BP-61C / BP-51C / BP-41C series301 and earlier
BP-70C / BP-60C / BP-50C / BP-40C series511 and earlier
MX-8081203 and earlier
MX-6171 / 5171 / 4171 / 3661 / 3161 / 2661
MX-6151 / 5151 / 4151 / 3631 / 2631
615 and earlier
BP-30C25203 and earlier
MX-6170 / 5170 / 4170 FN and FV804 and earlier
MX-6150 / 5150 / 4150 / 3650 / 3150 / 2650 FN and FV
MX-3630FN / MX-2630FN
804 and earlier
BP-C533WD / BP-C533WR410 and earlier
MX-C306W / MX-C305W522 and earlier
Model group (monochrome)Affected firmware
BP-70M90 / BP-70M75520 and earlier
BP-71M65 / 71M55 / 71M45301 and earlier
BP-70M65 / 70M55 / 70M45511 and earlier
MX-M1206 / MX-M1056301 and earlier
(311 with security kit installed)
MX-M7570 / MX-M6570457 and earlier
MX-M6071 / 5071 / 4071 / 3531414 and earlier
BP-30M35 / 30M31 / 30M28 / 30M31L304 and earlier
MX-M6070 / 5070 / 4070504 and earlier
MX-B455W405 and earlier
(406 with security kit installed)

Check the exact model listings against Sharp's original document. The tables above group models by series for readability.

What to do about the 78 models that get no fix

Table 2 is the awkward part. Sharp writes that firmware support has ended for these models with respect to the first impact. In other words, the hole is known to exist, and no means of closing it will be distributed. The list includes model numbers still very much in daily service β€” MX-5141FN, MX-3640FN, MX-2610FN, MX-M753, MX-M503N and many more.

Old hardware being disclosed with no patch is not unique to printers. We covered the Toshiba Dynabook driver flaw that ended with "please uninstall it" instead of a fix. The conclusion is the same: short of replacing the hardware, there is no complete solution.

So what do you do until then? Sharp lists four workarounds, all of them aimed at keeping an attacker from reaching the printer in the first place. Do not connect the MFP directly to the internet; keep it inside a network protected by a firewall or similar. Restrict access to the printer's web pages with a password. Change the default administrator and user passwords from their factory values and manage them properly. And review the audit log periodically for signs of suspicious access.

The first of the four does the most work. This flaw requires being able to touch the printer's web functions, so putting the machine somewhere unreachable from outside neutralizes it in practice. Put the other way round: the environments most at risk are those where the printer still holds a global IP address.

The PC-side scan software has a hole of its own

On that same July 31, Sharp published a second advisory (2026-005). It covers Network Scanner Tool Lite and Network Scanner Tool, the software bundled with Sharpdesk. These are resident Windows applications that take documents scanned on the MFP and drop them into a designated folder on a PC over the office LAN. If a Sharp MFP was installed, this software almost certainly came with it.

CVE-2026-62416: With default settings, anyone can drop files onto the PC

To receive scans, the tool runs an FTP server (a service that sits listening for file transfers) on the PC. With default settings, authentication does not take effect, and in JVN's phrasing files can be uploaded without restriction. Anyone who can reach that network can place files on that machine.

The impact Sharp describes is that a malicious file may be delivered and, once the user opens or runs it, other devices may then be attacked by way of that PC. JVN also notes the possibility of filling the disk until the machine stops working.

ProductAffectedFixed
Network Scanner Tool LiteV2.0.13.3 and earlierV2.1.0.2 or later
Network Scanner Tool
(bundled with Sharpdesk)
V6.1.1.8 and earlierV6.2.0.1 or later

Here, at least, a proper fix exists. Get the corrected application from Sharp's download site, then open System Options to confirm the version and check that a user name and password are set under Security Account Settings. If you cannot apply the update yet, the documented workaround is to open System Options, clear the checkbox labelled for use with network scanners that have no password function, and set a user name and password under Security Account Settings.

What actually happens when a printer gets targeted

For anyone thinking "it's only a printer," here is what has happened before.

In 2013, MFPs at several Japanese universities were found sitting directly reachable from the internet, with scanned documents readable by outsiders. Japan's IPA issued an advisory for system administrators that November, asking for four things: do not attach these machines to external networks unless required, restrict the traffic if you must, change the administrator password from its factory setting, and turn on access control. CVE-2026-60011 is structurally the same story thirteen years later β€” stored documents readable through a printer web function that outsiders can reach.

In 2019, Microsoft's threat intelligence team reported that a state-sponsored group had been using office printers and VoIP phones as entry points. Of the compromised devices, two still had factory default passwords and one was missing a security update. That is why "change the default password" and "update the firmware" are the countermeasures Sharp and Toshiba Tec both put front and centre β€” those are the two that have actually been broken.

JBMIA, the Japanese business machine industry association, publishes a case where an MFP was used as a stepping stone: the file server protocol it used was outdated, a virus spread through the office as a result, and the infection eventually reached a business partner, leading to a damages claim. The same association also documents a case where patent-related documents stored on an MFP were read by outsiders. On the printer side, we have also covered a Ricoh MFP and printer flaw that turned the device into a relay into the internal network.

The identifiers exist, but you cannot look them up in NVD

One thing stood out while researching this. Looking up all four identifiers in NVD, the US National Vulnerability Database that most of the world queries, returns "CVE ID Not Found" for every one of them β€” CVE-2026-60011, CVE-2026-63545, CVE-2026-63563 and CVE-2026-62416 alike.

NVD explains that although an identifier may have been assigned by CVE or a CNA, it will not appear in NVD while its status is RESERVED. The number is claimed, but the record has not been released as public data yet.

That has practical consequences. Most automated vulnerability management tools work from NVD's feed, so these four will not be flagged by them for the time being. For this disclosure, the only way to know whether you are affected is for a person to read JVN and the vendor advisories and match the model numbers by hand.

146 models last time, roughly 170 this time

This is not the first time Sharp and Toshiba Tec MFPs have appeared in the same JVN entry. A comparable disclosure landed in October 2024, and Security NEXT reported it as "146 Sharp and Toshiba Tec MFP models affected, half of them out of support". ASCII.jp and Mynavi TECH+ covered the same event.

This round is 164 Sharp models plus 6 from Toshiba Tec, roughly 170 in total, with 78 of the Sharp models receiving no corrected firmware. The scope has grown since last time. Note that the model counts are ours, arrived at by counting the names in the advisory β€” the document itself states no total.

As for market share, no primary source breaks the Japanese MFP market down by manufacturer. JBMIA publishes shipment statistics, but without per-vendor figures. Rankings such as "Sharp is fourth in Japan" circulate only on dealer websites and are not backed by published data.

At the time of writing, we could not find any Japanese media coverage of this particular disclosure. Given that several outlets reported the 2024 case within a day, coverage may still be coming.

What to do right now

Write down your printer's model number and check whether it sits in Table 1 or Table 2 of Sharp's advisory. If it is in Table 1, contact your dealer or Sharp Marketing Japan and request the firmware update. Because the advisory does not publish the fixed version numbers, this goes through the support contact. Owners of the affected Toshiba Tec models will likewise be guided through a software upgrade by their service provider.

If your model is in Table 2, no update is coming. Confirm as a first priority that the printer sits behind a firewall and is not directly reachable from outside, and check whether the administrator password is still the factory default. In practice, nobody ever changes the administrator password on a machine that arrived under a lease contract.

The PC-side Network Scanner Tool is something you can handle yourself. Update Lite to V2.1.0.2 or later, or the Sharpdesk-bundled version to V6.2.0.1 or later, and fill in Security Account Settings.

Finally, take one look at the printer's audit log. Practically no organization reviews it routinely, and that is how "we assumed nothing happened because we never looked" happens. Among Japanese network hardware vendors, disclosures that include end-of-support products keep appearing β€” see the Elecom router flaws for a recent example.

Summary

164 Sharp digital MFP models carry CVE-2026-60011, a flaw that lets stored document images be retrieved while bypassing login. CVE-2026-63545, where printing from USB storage produces an unrelated document, was disclosed at the same time. The third identifier, CVE-2026-63563, does not affect products for the Japanese market.

There are no reports of exploitation so far. The heaviest part of this case is that 78 models get no corrected firmware, leaving network isolation as the only available answer. The severity score of 6.9 is not dramatic, but this one should be read through its breadth and through the plain fact that some machines cannot be repaired.

Office printers keep running for years on whatever settings they arrived with. A disclosure like this is one of the few occasions anyone revisits them.

Frequently asked questions

Our printer is only on the office LAN. Is it still at risk?

The risk drops considerably. The flaw requires reaching the printer's web functions, so if it cannot be touched from outside, this becomes a secondary concern that matters only after someone is already inside. Watch out for setups where guest Wi-Fi is not separated from the office network.

We use a Toshiba Tec MFP. Are we affected?

Toshiba Tec's listed models are e-STUDIO 908 / 1058 / 1208 and 907 / 1057 / 1207, and the company states these products are deployed in the North American market only. If the model you use is not on that list, it is not part of this disclosure.

Where can I find the fixed firmware version numbers?

Neither Sharp's nor Toshiba Tec's advisory states the corrected version numbers or a release date. Both route this through the dealer or service provider.

Can I check whether data has already leaked?

The printer's audit log is the only lead, and Sharp lists reviewing it among the workarounds. Retention periods vary by model and configuration, so a complete look back may not be possible.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django