Observed arrival · 2026-09-17
Print Overrun Finds Attack Paths in the Paper Workflow
Independent security research documenting vulnerabilities in multifunction printers, fleet software, and enterprise document workflows.
Field notes
The project treats printing as a chain of services rather than a single endpoint, tracing jobs through spoolers, release queues, device storage, email, network shares, and cloud connectors. Its homepage lists three HP Advance / HP Output Central findings with CVSS scores from 8.8 to 9.3, including SYSTEM-level archive extraction and unauthenticated .xml file operations. The page also records CVE identifiers, publication dates, stated remediation status, and the independent researcher responsible.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue