Thursday, September 10, 2026

Xerox FreeFlow Core Vulnerability Allows Remote Code Execution — PoC Now Public

Security researchers have disclosed critical vulnerabilities in Xerox FreeFlow Core that enable unauthenticated remote attackers to execute arbitrary code on vulnerable systems.

The proof-of-concept exploits are now publicly available, raising immediate concerns for organizations using the popular print orchestration platform.

Critical Vulnerabilities Discovered

Cybersecurity firm Horizon3.ai discovered two severe vulnerabilities in Xerox FreeFlow Core: an XML External Entity (XXE) injection flaw tracked as CVE-2025-8355 and a path traversal vulnerability designated CVE-2025-8356.

AttributeCVE-2025-8355CVE-2025-8356
SeverityCriticalCritical
ImpactRemote Code Execution, SSRFRemote Code Execution, File Upload
Affected ProductXerox FreeFlow CoreXerox FreeFlow Core
Vulnerability TypeXML External Entity (XXE) InjectionPath Traversal
Patched Version8.0.58.0.5

Both vulnerabilities allow attackers to achieve remote code execution without any authentication requirements, making them particularly dangerous for internet-facing installations.

The discovery originated from an unusual customer support request where Horizon3.ai’s NodeZero platform detected XXE exploitation callbacks from a host that supposedly didn’t contain the vulnerable software.

This anomaly prompted deeper investigation that ultimately uncovered the widespread vulnerability in FreeFlow Core installations.

Technical Analysis and Impact

FreeFlow Core serves as a comprehensive print orchestration platform primarily deployed in commercial print shops, packaging providers, universities, and government agencies handling large-scale printing operations.

The platform’s complex architecture includes multiple services, with the JMF Client service on port 4004 being the primary attack vector.

The XXE injection vulnerability exploits improper XML parsing in the JMF (Job Message Format) message handling system.

Attackers can submit malicious XML requests to perform server-side request forgery attacks and access sensitive system information.

More critically, the path traversal flaw in the file processing mechanism allows attackers to upload webshells to publicly accessible directories, providing immediate remote access to compromised systems.

Xerox FreeFlow Core Vulnerability
Xerox FreeFlow Core Vulnerability

The combination of these vulnerabilities creates a particularly attractive target for cybercriminals, especially considering that print workflows often contain pre-release marketing materials and sensitive corporate information.

The platform’s requirement for relatively open network access further amplifies the risk exposure.

Xerox has addressed both vulnerabilities in FreeFlow Core version 8.0.5, released on August 8, 2025, following a responsible disclosure process initiated by Horizon3.ai in June 2025.

The company worked collaboratively with the researchers over two months to develop and test patches before public release.

Organizations running FreeFlow Core are strongly urged to upgrade immediately to version 8.0.5.

Given the public availability of proof-of-concept exploits and the severity of the vulnerabilities, delaying patching could result in complete system compromise.

The disclosure timeline demonstrates industry best practices, with initial contact established in June, vulnerability confirmation and patch development throughout July, and coordinated public disclosure in August.

This measured approach allowed Xerox adequate time to develop comprehensive fixes while ensuring the security community receives timely notification of the risks.

Security teams should prioritize scanning for vulnerable FreeFlow Core installations and implementing emergency patches where immediate upgrades aren’t feasible.

AWS Security Services: 10-Point Executive Checklist - Download for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits

OpenAI has announced its plans for a "Defense Factory,"...

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

Threat actors are impersonating corporate IT helpdesk staff in...

12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing

Quick Answer: For dedicated deny-by-default allowlisting, ThreatLocker and Airlock...

Related Articles

Recent News