Publication Date: September 30, 2026
Security Vulnerability Affecting Our Digital Multifunctional Systems
for the North American Market
Thank you for using our products.
It has been discovered that certain Digital Multifunctional Systems manufactured for the North American market contain a security vulnerability. We ask customers to update the firmware to the latest version.
Please refer to the table below for an overview of the vulnerability and the affected products.
| Affected models and firmware version |
Product: BP-1360M / BP-1250M Affected versions:
To confirm the firmware version of the device that you use, please follow the steps below:
|
|---|---|
| Vulnerability Description |
The devices may be vulnerable to path traversal attacks through crafted requests. To enable attackers to successfully attack the device using this vulnerability, the following conditions shall be fulfilled:
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.8 Note: The CVSS v4.0 score above is based on the assessment provided by FUJIFILM Business Innovation Corp. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Base Score 4.9 CVE-ID: CVE-2026-78249 CWE-ID: Path Traversal (CWE-22) |
| Possible impacts | If the above conditions are fulfilled, attackers may be able to access information stored on the device to which normal users cannot access. |
| Countermeasure | Sharp released updated firmware to remediate the vulnerability for the models listed as above. For details, consult your authorized Sharp service providers. |
| Mitigation measures |
To mitigate the security risks, ensure to protect your devices and apply the following operations:
By applying the above operations, you can reduce the risk of the affected devices being attacked by malicious third parties and of the information stored on the devices being leaked. |
| References |
For detailed countermeasure procedures, please refer to the product support page below. https://global.sharp/products/copier/info/info_security_2026-09.html |
| Acknowledgment | This vulnerability was reported to us by JPCERT/CC under the Information Security Early Warning Partnership. |
| Revision History |
|