securityonline.info 17 Sept 2026, 14:50 UTC

Critical HP Advance flaws let attackers seize print servers and run commands

Critical HP Advance flaws let attackers seize print servers and run commands
CyberSIXT Evidence Panel Source marked as original reporting

HP issued security updates on 16 September 2026 for three vulnerabilities in HP Advance software used for centralised printing and scanning. CVE-2026-89082 and CVE-2026-89083 are rated critical, with CVSS 4.0 scores of 9.3, while CVE-2026-89084 is rated 8.8. The flaws could allow an unauthenticated network attacker to gain elevated privileges, execute operating-system commands remotely or write arbitrary files on the server hosting the software. HP said the issues affect HP AC Print & Scan versions before V1R4.0.027 and HP Output Central versions before V1R4.0.029.

According to the report, the vulnerabilities involve improper input validation. An attacker could send crafted requests to an exposed HP Advance server, where inadequately sanitised data might be processed as malicious input. Successful exploitation could enable compromise of the print server and potentially provide a route into sensitive network areas or access to documents stored there. However, the report says there is no confirmed exploitation in the wild and no publicly available proof-of-concept code.

Administrators should upgrade HP AC Print & Scan to V1R4.0.027 or later and HP Output Central to V1R4.0.029 or later, following HP’s security advisory. The vendor has not provided a temporary mitigation, so applying the updates is the only verified remediation described.

View full article

Article by CyberSIXT