Sharp and Toshiba Copier Flaws: Turn On User Authentication
On July 31, Sharp and Toshiba Tec disclosed three flaws in their office MFPs, and NIST's vulnerability database published them August 3. The most practical one: affected models built for markets outside Japan, including the US, shipped with user authentication turned off. Turn it on, and ask your dealer for the firmware that fixes the other two.
Key takeaways
- On July 31, 2026, Sharp and Toshiba Tec disclosed three MFP vulnerabilities under JVNVU#98759887, and NIST's National Vulnerability Database published the CVEs on August 3.
- Under CVE-2026-63563, affected Sharp and Toshiba Tec MFP models built for markets outside Japan, including the US, shipped with user authentication turned off, exposing address book editing and Document Filing features.
- The vendors' remedy for CVE-2026-63563 is a workaround, enabling user authentication, rather than a firmware update, so check the setting yourself.
- Updated firmware fixes CVE-2026-60011 and CVE-2026-63545; Toshiba Tec tells customers to ask their service company to install it.
- Offices that store client personal information should know California's 30-day breach-notification deadline, in effect since January 1, 2026.
On Friday, July 31, Sharp and Toshiba Tec each published security advisories for their office multifunction printers (MFPs), coordinated through JPCERT/CC and published on Japan Vulnerability Notes (JVN) as JVNVU#98759887, "Multiple vulnerabilities in Sharp and Toshiba Tec MFPs," according to JVN, Sharp and Toshiba Tec. On Monday, August 3, the U.S. National Vulnerability Database published the three CVEs.
Two of the three flaws are fixed by updated firmware, which on leased or dealer-serviced copiers is usually installed by the dealer. The third is different: it's a factory default, and it's the one worth checking this week. Affected Sharp and Toshiba Tec models built for markets outside Japan, which includes the US, shipped with user authentication turned off.
What did Sharp and Toshiba Tec disclose?
Three vulnerabilities in their MFPs: one lets someone on the network pull stored images without logging in, one leaves print data cached on the machine, and one is an insecure default setting. Here's the summary from JVN, NVD and the vendors' advisories.
| CVE | What it means | Severity | Vendors' remedy |
|---|---|---|---|
| CVE-2026-60011 | Tampered requests to the MFP's web interface can retrieve stored image data without authentication | Medium, 6.9 (CVSS v4.0) | Updated firmware |
| CVE-2026-63545 | Data cached during printing isn't cleared, so other users can later access it; requires physical access | Low, 2.4 | Updated firmware |
| CVE-2026-63563 | Affected models for markets outside Japan shipped with user authentication off, exposing address book editing and Document Filing features | Medium, 6.9 (CVSS v4.0) | Turn on user authentication |
CVE-2026-60011 is an authentication bypass. The machines fail to properly authorize requests that directly access certain stored image data, so someone who tampers with requests to the MFP's web interface can retrieve that data without logging in, according to NVD, JVN and SentinelOne's vulnerability database. NVD shows JPCERT/CC's rating: Medium, 6.9 under CVSS v4.0.
CVE-2026-63545 is lower risk. The machines cache data internally when printing and don't clear it, so other users can later get at it, but it's rated Low (2.4) and requires physical access to the device, per JVN, OpenCVE and INCIBE-CERT.
Why does the authentication default matter most?
Because it's the flaw you can fix yourself today, and the vendors' remedy for it is a settings change, not a firmware update. Under CVE-2026-63563, affected products for markets outside Japan shipped with the user authentication feature disabled, so address book editing and a range of Document Filing (stored-document) features can be used without signing in, according to JVN, Toshiba Tec and SentinelOne. Products made for the Japanese market aren't affected. It's rated Medium, 6.9 under CVSS v4.0 (JPCERT/CC's score, the same as the authentication bypass), according to NVD, OpenCVE and SentinelOne.
The vendors' workaround is to turn user authentication on, which puts the job in your hands, or your dealer's.
In practical terms, anyone who can reach the machine over your office network could use those features without identifying themselves. The address book is the easiest to picture. For example, if someone changed a scan-to-email entry, scans meant for your bookkeeper could quietly go somewhere else.
Is my office's machine affected?
If you have a Sharp or Toshiba Tec MFP built for the US market, the authentication default is the first thing to check. Whether your specific model is on the affected lists, and whether it needs the firmware fixes, depends on the model and its firmware version. The vendors publish those details, so check Sharp's advisory and Toshiba Tec's notice for your model rather than relying on a summary. If the machine is leased or under a service contract, your dealer can tell you the model and current firmware version.
How do you check that user authentication is turned on?
Start with a one-minute test at the machine: walk up and try to open the address book or Document Filing without signing in. If the machine never asks you to sign in or enter a user code, authentication is very likely off.
Menu names vary by model, so we won't guess at them. In general, an administrator signs in to the MFP's web page (type the printer's IP address into a browser on an office PC) or to the administrator settings on the control panel, finds the user control or authentication settings, turns on user authentication, and sets up staff accounts or codes. Because this changes how everyone uses the machine, set up the accounts first, then switch it on, then test printing, copying and scanning from a couple of desks. If your dealer manages the machine, ask them to do it.
While you're in the settings, three general best practices (ours, not quotes from the advisories), which our list of printer security features covers in more depth:
- Change the default administrator password and require a password for the machine's web page.
- Keep the MFP off the public internet, behind your office firewall.
- Delete stored jobs you no longer need from Document Filing, turn on automatic deletion if your model offers it, and don't treat the copier as a filing cabinet.
What about the firmware fixes?
Sharp and Toshiba Tec released updated firmware for CVE-2026-60011 and CVE-2026-63545, according to JVN, Sharp and Toshiba Tec. Toshiba Tec tells customers to ask their service company to update the main-unit software. On most leased or dealer-serviced machines, whatever the brand, your dealer handles firmware, so call them.
Ask three questions: Is our model on the affected list? When will you install the update? Can you confirm the new firmware version in writing? If you're not sure who is responsible for firmware under your agreement, last week's contract checklist shows where to look.
Because CVE-2026-63545 needs physical access, it also helps to keep the MFP where staff can see it, not in an unattended hallway or shared lobby.
What about Sharp's Network Scanner Tool?
Also on July 31, Sharp disclosed CVE-2026-62416 (JVNVU#92540957), a separate flaw in its Network Scanner Tool and Network Scanner Tool Lite, according to Sharp, JVN and NVD. These are Windows apps that act as FTP servers to receive scans from MFPs, and in their initial configuration anyone can upload files to them without authentication. Affected versions include Network Scanner Tool Lite V2.0.13.3 and earlier, plus older versions of the Network Scanner Tool bundled with Sharpdesk.
Sharp's mitigation: turn off "Allow anonymous FTP log-in" and set a custom FTP log-in user name and password. If your office scans to a PC with either tool, do that now and check Sharp's advisory for current versions.
What this means for San Fernando Valley offices
The authentication default isn't a far-off problem. It affects models built for markets outside Japan, which puts affected US-market Sharp and Toshiba Tec MFPs, like those in Valley offices, in scope.
For law, medical, accounting and real estate offices, the concern is what the machine stores: scanned images can include client or patient personal information. California's breach-notification law (Civil Code 1798.82, as amended by SB 446, effective January 1, 2026) requires businesses to notify California residents within 30 calendar days of discovering a breach of their unencrypted personal information. If more than 500 residents are notified, a sample notice must go to the Attorney General within 15 calendar days of notifying consumers, with exceptions for law-enforcement needs and for determining the breach's scope. That's according to the Civil Code, the California Attorney General, Pillsbury and Jackson Lewis.
Whether exposed images on a copier add up to a notifiable breach depends on what they contained, which is a question for your attorney. It's far easier to turn on a setting now than to work through that question later. Medical offices should also read our Sherman Oaks guide to medical office printers and HIPAA, and anyone storing client files should see our guide to secure document printing.
What to do now
- List every Sharp and Toshiba Tec MFP in the office, with its model name and who services it.
- Check each model against Sharp's advisory and Toshiba Tec's notice.
- Confirm user authentication is on; if it isn't, set up staff accounts and turn it on, or have your dealer do it.
- Change the default administrator password and require a password for the machine's web page.
- Ask your dealer or service company to install the updated firmware and confirm the new version in writing.
- Delete stored jobs you don't need from Document Filing and stop using it as long-term storage.
- If you use Sharp Network Scanner Tool or Network Scanner Tool Lite, turn off anonymous FTP log-in and set a custom user name and password.
- Decide now who calls your attorney if a device ever exposes client data, so California's 30-day clock doesn't catch you flat-footed.
If you'd like help checking these settings across your machines, book a free virtual consultation. If you'd rather we do the hands-on work, our security hardening service runs $299 to $599.
Frequently asked questions
- What vulnerabilities did Sharp and Toshiba Tec disclose in July 2026?
- On July 31, 2026, Sharp and Toshiba Tec disclosed three MFP flaws under JVNVU#98759887: CVE-2026-60011, an authentication bypass exposing stored image data; CVE-2026-63545, cached print data left uncleared; and CVE-2026-63563, affected models for markets outside Japan shipped with user authentication off. NIST's National Vulnerability Database published them on August 3.
- Are US Sharp and Toshiba copiers affected by the authentication default?
- US-market machines are in scope if the model is on the vendors' affected lists. CVE-2026-63563 covers affected Sharp and Toshiba Tec MFPs built for markets outside Japan, which shipped with user authentication disabled; Japanese-market units are not affected. Check the vendor's advisory for your model, confirm user authentication is turned on, and change the default administrator password.
- Does a firmware update fix CVE-2026-63563?
- No. For CVE-2026-63563, Sharp and Toshiba Tec recommend a workaround, enabling user authentication, rather than a firmware change. Updated firmware addresses the other two flaws, CVE-2026-60011 and CVE-2026-63545. Toshiba Tec tells customers to ask their service company to install it, and on leased machines the dealer usually handles firmware.
- Do I have to report a copier data exposure in California?
- Possibly. California's breach-notification law, as amended by SB 446 effective January 1, 2026, requires notifying affected residents within 30 calendar days of discovering a breach of their unencrypted personal information. Whether a copier exposure qualifies depends on what the stored images contained, so talk to your attorney promptly.
Sources
Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.
- JVNVU#98759887: Multiple vulnerabilities in Sharp and Toshiba Tec MFPs — JVN (JPCERT/CC and IPA), 2026-07-31
- Product Security Advisory 2026-004 — Sharp Corporation, 2026-07-31
- Response to vulnerability in some Toshiba Tec's digital multi-function peripherals — Toshiba Tec Corporation, 2026-07-31
- CVE-2026-60011 — NIST National Vulnerability Database, 2026-08-03
- CVE-2026-63563 — NIST National Vulnerability Database, 2026-08-03
- CVE-2026-60011 — SentinelOne vulnerability database, 2026-08-03
- CVE-2026-63563 — SentinelOne vulnerability database, 2026-08-03
- CVE-2026-63563 — OpenCVE, 2026-08-03
- CVE-2026-63545 — OpenCVE, 2026-08-03
- CVE-2026-63545 — INCIBE-CERT
- Product Security Advisory 2026-005 (Network Scanner Tool) — Sharp Corporation, 2026-07-31
- JVNVU#92540957: Sharp Network Scanner Tool insecure initial configuration — JVN (JPCERT/CC and IPA), 2026-07-31
- CVE-2026-62416 — NIST National Vulnerability Database
- California Civil Code Section 1798.82 — California Legislative Information
- Data Security Breach Reporting — California Attorney General
- California Data Breach Notification Requirements — Pillsbury Winthrop Shaw Pittman
- California Sets 30-Day Deadline for Data Breach Notifications — Workplace Privacy Report (Jackson Lewis), 2025-10
- California Tightens Data Breach Notification Timelines, Imposes 30-Day Notice Requirement — Data Protection Report (Norton Rose Fulbright), 2025-11
About Valley Printer Pros Team
Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.
Get Expert AdviceServing San Fernando Valley Businesses
We provide on-site printer consulting, setup, and lease escape support across the Valley:
Related Articles
On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.
Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.
On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.
Need Help with Your Printer Decisions?
Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.