Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · xerox

xerox

· 17 Critical

Total CVEs

119

Critical

17

Products

299

Search All CVEs →

119

Products (299)

workcentre20 CVEsworkcentre 25512 CVEsworkcentre 26512 CVEsworkcentre 27512 CVEsworkcentre 23812 CVEsworkcentre 23212 CVEsworkcentre 24512 CVEsaltalink c80359 CVEsaltalink c8035 firmware9 CVEsworkcentre ec78368 CVEsaltalink c80458 CVEsaltalink c8045 firmware8 CVEsaltalink c80558 CVEsaltalink c8055 firmware8 CVEsaltalink c80708 CVEsaltalink c8070 firmware8 CVEsworkcentre ec7856 firmware8 CVEsworkcentre ec78568 CVEsworkcentre ec7836 firmware8 CVEsworkcentre 7970i firmware8 CVEsworkcentre 7970i8 CVEsworkcentre 7970 firmware8 CVEsworkcentre 79708 CVEsworkcentre 7855 firmware8 CVEsworkcentre 78558 CVEsworkcentre 7845 firmware8 CVEsworkcentre 78458 CVEsworkcentre 7835 firmware8 CVEsworkcentre 78358 CVEsworkcentre 7830 firmware8 CVEsworkcentre 78308 CVEsworkcentre 7225 firmware8 CVEsworkcentre 72258 CVEsaltalink b8045 firmware8 CVEsaltalink b80558 CVEsworkcentre 7220 firmware8 CVEsaltalink b8055 firmware8 CVEsworkcentre 72208 CVEsworkcentre 6655i firmware8 CVEsworkcentre 6655i8 CVEsworkcentre 6655 firmware8 CVEsworkcentre 66558 CVEsaltalink b80658 CVEsaltalink b8065 firmware8 CVEsaltalink b80758 CVEsaltalink b8075 firmware8 CVEsaltalink b80908 CVEsaltalink b80458 CVEsaltalink b8090 firmware8 CVEsaltalink c80308 CVEsaltalink c8030 firmware8 CVEsfreeflow core8 CVEsphaser 33208 CVEsphaser 3320 firmware8 CVEsworkcentre 3655i firmware8 CVEsworkcentre 3655i8 CVEsworkcentre 3655 firmware8 CVEsworkcentre 36558 CVEsworkcentre 5890 firmware7 CVEsworkcentre 5890i7 CVEsworkcentre 58757 CVEsworkcentre 5875 firmware7 CVEsworkcentre 5890i firmware7 CVEsworkcentre 5875i7 CVEsworkcentre 58657 CVEsworkcentre 7225i7 CVEsworkcentre 7225i firmware7 CVEsworkcentre 5865i7 CVEsworkcentre 5875i firmware7 CVEsworkcentre 58907 CVEsworkcentre 5865 firmware7 CVEsworkplace suite7 CVEsworkcentre 5865i firmware7 CVEsworkcentre 7830i6 CVEsworkcentre 7855i firmware6 CVEsworkcentre 7855i6 CVEsworkcentre 7845i firmware6 CVEsworkcentre 7845i6 CVEsworkcentre 7835i firmware6 CVEsworkcentre 7835i6 CVEsworkcentre 7830i firmware6 CVEsworkcentre 5845 firmware6 CVEsworkcentre 7220i firmware6 CVEsworkcentre 7220i6 CVEsworkcentre 58456 CVEsworkcentre 35455 CVEsworkcentre 21285 CVEsversalink c70255 CVEsversalink c4055 CVEsversalink c5055 CVEsworkcentre 5900i firmware5 CVEsversalink c70305 CVEsversalink c6055 CVEsworkcentre 59005 CVEsversalink b4055 CVEsversalink c70205 CVEsworkcentre 5900 firmware5 CVEsworkcentre 5900i5 CVEsversalink c70005 CVEsworkcentre 26365 CVEsdocument centre 5354 CVEscopycentre c654 CVEscopycentre c754 CVEscopycentre c904 CVEsdocument centre 2654 CVEsdocument centre 3324 CVEsdocument centre 3404 CVEsdocument centre 4204 CVEsdocument centre 4904 CVEsdocument centre 5554 CVEsdocutech 61104 CVEsdocutech 61154 CVEsfreeflow print server4 CVEsversalink b4004 CVEsversalink b405 firmware4 CVEsversalink b6004 CVEsversalink b6054 CVEsversalink b605 firmware4 CVEsversalink b6104 CVEsversalink b6154 CVEsversalink b615 firmware4 CVEsversalink b70254 CVEsversalink b70304 CVEsversalink b70354 CVEsversalink c4004 CVEsversalink c405 firmware4 CVEsversalink c5004 CVEsversalink c505 firmware4 CVEsversalink c6004 CVEsversalink c605 firmware4 CVEsversalink c7000 firmware4 CVEsversalink c7020 firmware4 CVEsversalink c7025 firmware4 CVEsversalink c7030 firmware4 CVEsversalink c80004 CVEsversalink c90004 CVEsworkcentre 65154 CVEsworkcentre 6515 firmware4 CVEscopycentre c75 firmware3 CVEscopycentre c65 firmware3 CVEsversalink b610 firmware3 CVEsversalink b7035 firmware3 CVEsversalink c8000 firmware3 CVEsphaser 6510 firmware3 CVEsphaser 65103 CVEsworkcentre 753 CVEsversalink c8000w3 CVEsworkcentre pro 75 firmware3 CVEsversalink c9000 firmware3 CVEsversalink b7030 firmware3 CVEsworkcentre 59453 CVEsworkcentre 5945 firmware3 CVEsworkcentre 59553 CVEsworkcentre 5955 firmware3 CVEsversalink b600 firmware3 CVEscentreware web3 CVEsworkcentre 653 CVEsworkcentre 903 CVEsversalink b400 firmware3 CVEsworkcentre pro 903 CVEsversalink b7025 firmware3 CVEsversalink c400 firmware3 CVEsworkcentre pro 90 firmware3 CVEsversalink c500 firmware3 CVEscopycentre c90 firmware3 CVEsworkcentre pro 653 CVEsworkcentre pro 65 firmware3 CVEsversalink c600 firmware3 CVEsworkcentre pro 753 CVEsworkcentre m1652 CVEsworkcentre 5955i2 CVEsworkcentre 5955i firmware2 CVEsworkcentre m1752 CVEscolorqube 8580 firmware2 CVEscolorqube 85802 CVEsworkcentre m352 CVEsworkcentre 1652 CVEsworkcentre 1752 CVEsworkcentre 40 color2 CVEsworkcentre m452 CVEsworkcentre 452 CVEsworkcentre 32 color2 CVEsworkcentre 352 CVEsversalink c8000w firmware2 CVEsxmpie ustore2 CVEsworkcentre m552 CVEsdocushare2 CVEsdocument centre 2402 CVEsdocument centre 5452 CVEsdocument centre 4802 CVEsdocument centre 4702 CVEsdocument centre 4602 CVEsdocument centre 4402 CVEsdocument centre 4322 CVEsdocument centre 4302 CVEsdocument centre 4262 CVEsdocument centre 4252 CVEsdocument centre 2552 CVEsdocument centre 2302 CVEsdocument centre 2202 CVEsworkcentre 5945i2 CVEsworkcentre 5945i firmware2 CVEsworkcentre 552 CVEsworkcentre 7755 firmware1 CVEsworkcentre 77651 CVEsworkcentre 7765 firmware1 CVEsworkcentre 77751 CVEsworkcentre 7775 firmware1 CVEscolorqube 93011 CVEscolorqube 9203 firmware1 CVEscolorqube 92031 CVEscolorqube 9202 firmware1 CVEscolorqube 92021 CVEscolorqube 9201 firmware1 CVEscolorqube 92011 CVEscolorqube 8900 firmware1 CVEscolorqube 89001 CVEscolorqube 8700 firmware1 CVEscolorqube 87001 CVEsatlalink firmware1 CVEsatlalink c80701 CVEsatlalink c80551 CVEsatlalink c80451 CVEsatlalink c80351 CVEsatlalink c80301 CVEsatlalink b80901 CVEsatlalink b80751 CVEsatlalink b80651 CVEsatlalink b80551 CVEsversalink b7130 firmware1 CVEsversalink b71351 CVEsversalink b7135 firmware1 CVEsversalink b71301 CVEsversalink b7125 firmware1 CVEsversalink b71251 CVEsatlalink b80451 CVEsversalink c71201 CVEsversalink c7120 firmware1 CVEsversalink c71251 CVEsversalink c7125 firmware1 CVEsversalink c71301 CVEsversalink c7130 firmware1 CVEsxerox 41101 CVEsxerox 45901 CVEsversalink firmware1 CVEsprimelink c9070 firmware1 CVEsprimelink c90701 CVEsprimelink c9065 firmware1 CVEsprimelink c90651 CVEsprimelink b9136 firmware1 CVEsprimelink b91361 CVEsprimelink b9125 firmware1 CVEsprimelink b91251 CVEsworkcentre 35501 CVEsworkcentre 3550 firmware1 CVEsprimelink b9110 firmware1 CVEsprimelink b91101 CVEsprimelink b9100 firmware1 CVEsprimelink b91001 CVEsworkcentre 56321 CVEsworkcentre 56381 CVEsworkcentre 56451 CVEsworkcentre 56551 CVEsworkcentre 56651 CVEsworkcentre 56751 CVEsworkcentre 56871 CVEsworkcentre 58551 CVEsworkcentre 5855 firmware1 CVEsphaser 4622 firmware1 CVEsphaser 46221 CVEsphaser1 CVEsfiery webtools1 CVEsdocuprint n401 CVEsworkcentre 64001 CVEsworkcentre 6400 firmware1 CVEsworkcentre 6400 net controller1 CVEsworkcentre 6400 system software1 CVEsxerox 45951 CVEsdocucolor 4lp1 CVEsworkcentre 72001 CVEsworkcentre 7200 firmware1 CVEsworkcentre 7200i1 CVEsworkcentre 7200i firmware1 CVEscolorqube 9303 firmware1 CVEscolorqube 93031 CVEscolorqube 9302 firmware1 CVEscolorqube 93021 CVEscolorqube 9301 firmware1 CVEsworkcentre 75251 CVEsworkcentre 7525 firmware1 CVEsworkcentre 75301 CVEsworkcentre 7530 firmware1 CVEsworkcentre 75351 CVEsworkcentre 7535 firmware1 CVEsworkcentre 75451 CVEsworkcentre 7545 firmware1 CVEsworkcentre 75561 CVEsworkcentre 7556 firmware1 CVEsworkcentre 77551 CVEs

Recent Vulnerabilities

View all 119
CVE-2026-2252HIGH 7.5

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.  Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on -  https://www.support.xerox.com/en-us/product/core/downloads

CVE-2026-2251CRITICAL 9.8

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads

CVE-2026-1769MEDIUM 5.3

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVE-2025-8356CRITICAL 9.8

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

CVE-2025-8355HIGH 7.5

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

CVE-2024-55931MEDIUM 6.5

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.  The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

CVE-2024-55930MEDIUM 6.7

Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

CVE-2024-55929MEDIUM 5.3

A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from trusted sources.

CVE-2024-55928MEDIUM 6.5

Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption

CVE-2024-55927HIGH 7.6

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.

CVE-2024-55926HIGH 7.6

A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data

CVE-2024-55925HIGH 7.5

In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.

CVE-2024-47559HIGH 7.6

Authenticated RCE via Path Traversal

CVE-2024-47558HIGH 7.6

Authenticated RCE via Path Traversal

CVE-2024-47557HIGH 8.3

Pre-Auth RCE via Path Traversal

CVE-2024-47556HIGH 8.3

Pre-Auth RCE via Path Traversal

CVE-2023-46327MEDIUM 5.9

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2022-45897MEDIUM 6.5

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.

CVE-2022-26572HIGH 7.5

Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.

CVE-2021-37354CRITICAL 9.8

Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-23321MEDIUM 4.8

A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.

CVE-2022-23320HIGH 7.5

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

CVE-2022-23968HIGH 7.5

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."

CVE-2019-10881CRITICAL 9.8

Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.

CVE-2021-28672CRITICAL 9.8

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35 before 58.65.51 and 58.59.11 (Bridge), C400 before 67.65.51 and 67.59.01 (Bridge), C405 before 68.65.51 and 68.59.01 (Bridge), C500/C600 before 61.65.51 and 61.59.01 (Bridge), C505/C605 before 62.65.51 and 62.59.01 (Bridge), C7000 before 56.65.51 and 56.59.01 (Bridge), C7020/25/30 before 57.65.51 and 57.59.01 (Bridge), C8000/C9000 before 70.65.51 and 70.59.01 (Bridge), C8000W before 72.65.51 allows remote attackers to execute arbitrary code through a buffer overflow in Web page parameter handling.