CVE-2026-2251Disclosure(xerox / freeflow_core)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch xerox freeflow_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freeflow_core

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 6 mentions (2026-02-27); latest day: 1
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
freeflow_core

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-02-27: 6Mentions · 2026-03-04: 1Patch / Workaround · 2026-02-27: 2Technical Details · 2026-02-27: 6Technical Details · 2026-03-04: 102-2703-04
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-276
Disclosure4Patch2
2026-03-041
Disclosure1
Full discourse7 posts
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-2251 - CRITICAL Xerox FreeFlow Core 🤖 AI Summary: Path traversal flaw in Xerox FreeFlow Core enables remote code execution. Affects versions up to 8.0.7. ThreatScore: 98/100 🔗 http://threatmonitor.io/cve/CVE-2026-2251 #cybersecurity #infosec #CVE

    Post summary

    The post announces a critical path traversal vulnerability (CVE‑2026‑2251) in Xerox FreeFlow Core that permits remote code execution, affecting versions up to 8.0.7.

    1001044
    9 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2251 (CVSS:9.8, CRITICAL) is Analyzed. Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows..https://nvd.nist.gov/vuln/detail/CVE-2026-2251 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-2251, a critical path traversal flaw in Xerox FreeFlow Core, noting its CVSS score and linking to the NVD entry, but offers no PoC, exploit, patch, or active exploitation details.

    0000028
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2251 Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. Th… https://www.cve.org/CVERecord?id=CVE-2026-2251

    Post summary

    The text announces a path‑traversal vulnerability in Xerox FreeFlow Core that could lead to remote code execution, but provides no proof of concept, exploit code, or patch information.

    0000094
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2251 - Critical Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xer... https://www.thehackerwire.com/vulnerability/CVE-2026-2251/ https://t.co/MqrjdG3cYB

    Post summary

    The post announces a new critical path‑traversal flaw in Xerox FreeFlow Core that can lead to remote code execution, but provides no evidence of exploitation, PoC, or fixes.

    0000032
    119 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-2251: CRITICAL] Path Traversal vulnerability in Xerox FreeFlow Core allows unauthorized access and RCE. Update to version 8.1.0 to fix it. Download link: https://www.support.xerox.com/en-us/product/c...#cve,CVE-2026-2251,#cybersecurity https://cvefind.com/CVE-2026-2251

    Post summary

    Xerox FreeFlow Core has a critical path traversal flaw (CVE‑2026‑2251) that can lead to unauthorized access and remote code execution; updating to version 8.1.0 resolves the issue.

    0000035
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-2251** is a **Path Traversal** vulnerability present in **Xerox FreeFlow Core** versions up to and including **8.0.7**. The core issue stems from improper validation or sanitization of file path inputs, allowing an attacker to manipulate file paths to access restricted directories on the server. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-2251

    Post summary

    The post announces a path traversal vulnerability in Xerox FreeFlow Core 8.0.7, describing how attackers could manipulate file paths to access restricted directories, but does not provide PoC, exploit, or patch information.

    0000029
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-2251 in Xerox FreeFlow Core (≤8.0.7) allows unauth RCE via path traversal. Upgrade to 8.1.0 ASAP to protect print workflows! 🛡️ https://radar.offseq.com/threat/cve-2026-2251-cwe-22-improper-limitation-of-a-path-309f50e5 #OffSeq #Infosec #PrintSecurity https://t.co/QbuBfhrc0d

    Post summary

    The tweet announces a critical unauthenticated RCE via path traversal in Xerox FreeFlow Core (CVE-2026-2251) and urges users to upgrade to version 8.1.0 to mitigate the risk.

    0000030
    270 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxeroxfreeflow_core---

Explore more