# CVE-2026-63226

## Summary

- **CVE ID:** CVE-2026-63226
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N)
- **CWE:** CWE-923
- **Published:** Jul 23, 2026
- **Last Modified:** Jul 24, 2026

## Description

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

## Affected Products

- Ricoh Company — Ricoh printers and Multifunction Printers (MFPs) (refer to the information provided by the developer.)

## References

- [CNA](https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000006)
- [CNA](https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000006)
- [CNA](https://jvn.jp/en/jp/JVN32082029/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._