CVE-2025-26506
critical-risk
Published 2025-02-14
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
Do I need to act?
~
6.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (20)
499Q9E Firmware
499Q9F Firmware
499R0A Firmware
499R0E Firmware
499R0F Firmware
4Ra80A Firmware
4Ra80E Firmware
4Ra80F Firmware
4Ra81A Firmware
4Ra81E Firmware
4Ra81F Firmware
4Ra81Fr Firmware
4Ra82A Firmware
4Ra82E Firmware
4Ra82F Firmware
4Ra82Fr Firmware
4Ra83A Firmware
4Ra83E Firmware
4Ra83F Firmware
4Ra84A Firmware
Affected Vendors
References (1)
71
/ 100
critical-risk
Severity
32/34 · Critical
Exploitability
9/34 · Low
Exposure
30/34 · Critical