HP HP

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any HP product.

RSS Feeds for HP security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in HP products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by HP Sorted by Most Security Vulnerabilities since 2018

HP Instantos56 vulnerabilities

Hp Ux49 vulnerabilities

HP Oneview22 vulnerabilities

HP Support Assistant16 vulnerabilities

HP Pc Bios12 vulnerabilities

HP Icewall Federation Agent10 vulnerabilities

HP Arcsight Logger10 vulnerabilities

HP Arubaos9 vulnerabilities

HP Icewall File Manager7 vulnerabilities

HP Thinpro6 vulnerabilities

HP Security Manager5 vulnerabilities

HP Thinpro Linux4 vulnerabilities

HP Omen Gaming Hub4 vulnerabilities

HP Systems Insight Manager3 vulnerabilities

HP Asset Manager2 vulnerabilities

HP Jumpstart2 vulnerabilities

HP Sound Research2 vulnerabilities

By the Year

In 2026 there have been 19 vulnerabilities in HP with an average score of 7.8 out of ten. Last year, in 2025 HP had 13 security vulnerabilities published. That is, 6 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 19 7.80
2025 13 0.00
2024 41 7.95
2023 67 8.22
2022 36 7.77
2021 14 8.09
2020 90 8.77
2019 155 7.84
2018 76 5.74

It may take a day or so for new HP vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent HP Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-82346 Aug 31, 2026
HP ImageDiags <5.0.0.36 PrivEsc via Insufficient Access Controls A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
CVE-2026-12556 Aug 24, 2026
HP Easy Start <2.16.7.260722 Privilege Escalation Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-12555 Aug 24, 2026
Privilege Escalation in HP Easy Start <2.16.7.260722 (macOS) Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-12554 Aug 24, 2026
HP Easy Start macOS < 2.16.7.260722 privilege escalation Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-75946 Aug 21, 2026
OMEN Gaming Hub <1101.2608.0.0 Local Priv Esc Vulnerability A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Omen Gaming Hub
CVE-2026-17639 Aug 17, 2026
HP Smart Tank AllInOne Printers DoS via Concurrent HTTP Requests Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
CVE-2026-12553 Aug 17, 2026
HP Web Jetadmin DLL Hijacking Allows Unauth File RW HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism.
CVE-2026-13753 Jul 06, 2026
HP Deskjet 2800 Webserver Missing Auth: Unauth GET Exposes WiFi Credentials Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
CVE-2026-2891 Jul 01, 2026
Poly Voice IP Devices: Inoperability via Malformed SIP Data The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-7539 Jun 24, 2026
HP Accessory WMI Provider Installer: PrivEsc & ACE via Faulty Install A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.
CVE-2026-3291 May 06, 2026
Samsung Print Service Plugin Android Info Disclosure Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-4682 Apr 15, 2026
RCE via WSD Scan Buffer Overflow in HP DeskJet All-in-One Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windowsbased network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities.
CVE-2026-4667 Apr 15, 2026
HP System Optimizer Privilege Escalation Vulnerability HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.
Omen Gaming Hub
CVE-2026-0754 Mar 03, 2026
Extractable Test Key/Cert on Poly Voice Device: SIP Bypass An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
CVE-2026-2832 Feb 20, 2026
Samsung MultiXpress Info Disclosure via Unauthenticated APIs Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.
CVE-2026-1578 Feb 13, 2026
XSS in HP App for Android via Outdated Version HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
CVE-2026-1997 Feb 10, 2026
CVE-2026-1997 HP OfficeJet Pro CORS Misconfig Grants UnAuth Cross-Origin Access Certain HP OfficeJet Pro printers may expose information if CrossOrigin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Proclass devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
CVE-2026-1996 Feb 10, 2026
Denial-of-Service via IPP Mishandled Requests in HP OfficeJet Pro Printers Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.
CVE-2019-25305 Feb 06, 2026
JumpStart 0.6.0.0 Unquoted Service Path Vulnerability in jswpbapi JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.
Jumpstart
CVE-2025-14432 Dec 16, 2025
Teams Admin Center Log Exposes Sensitive Data During Config Changes In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
CVE-2025-11761 Nov 03, 2025
HP Client Management Script Library PRIVESC via install script (CVE-2025-11761) A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability.
CVE-2025-43017 Oct 28, 2025
HP ThinPro 8.1 SP8 System Management App ID Verification Vulnerability HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
Thinpro
CVE-2025-10577 Oct 15, 2025
HP Audio Package Sound Research SECOMN64 Driver Privilege Escalation Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities
Sound Research
CVE-2025-10576 Oct 15, 2025
HP Audio SECOMN64 Driver Privilege Escalation Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities.
Sound Research
CVE-2023-6215 Oct 07, 2025
HP Sure Start BIOS Intel Flash Descriptor Vulnerability (CVE-2023-6215) A potential security vulnerability has been identified in HP Sure Starts protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential vulnerability.
Sure Start
CVE-2025-10578 Oct 01, 2025
hp SA <9.47.41: Local Priv Esc via File Write A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
Support Assistant
CVE-2025-10568 Sep 19, 2025
HyperX NGENUITY: arbitrary code exec via software HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability.
CVE-2024-13980 Aug 27, 2025
H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft POST requests with forged javax.faces.ViewState parameters, potentially leading to arbitrary command execution. This flaw does not require authentication and may be exploited without session cookies. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-28 UTC.
Intelligent Management Center
CVE-2012-10026 Aug 05, 2025
Asset-Manager WP Plugin 2.0- File Upload RCE via upload.php The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once uploaded, the attacker can execute the file via a direct HTTP GET request, resulting in remote code execution under the web servers context.
Asset Manager
CVE-2025-43023 Jul 28, 2025
HP LIP Weak DSA Signature Key Vulnerability A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).
CVE-2025-43026 Jun 05, 2025
HP Support Assistant <9.44.18.0: Local PrivEsc via File Write A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
Support Assistant
CVE-2025-1697 Apr 18, 2025
Local Priv Escalation in HP Touchpoint Analytics Service <4.2.2439 A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing software updates to mitigate this potential vulnerability.
CVE-2024-42508 Oct 18, 2024
Auth Info Disclosure CVE-2024-42508 This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
Oneview
CVE-2024-42500 Sep 09, 2024
HP-UX NFSv4 DoS Vulnerability HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.
Hp Ux
CVE-2024-7720 Aug 27, 2024
HP Security Manager RCE via OpenSource Libs HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.
Security Manager
CVE-2024-8105 Aug 26, 2024
UEFI PK Compromise Enables Malicious Firmware Attack A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.
CVE-2024-41912 Aug 07, 2024
Poly Clariti Manager Firmware <10.10.2.2 Acct Control Flaw A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.
Poly Clariti Manager Firmware
CVE-2024-42398 Aug 06, 2024
Unauthenticated DoS via Soft AP PAPI Exploit Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
Instantos
CVE-2024-42400 Aug 06, 2024
Unauth DoS in Soft AP Daemon via PAPI Prevents AP Functionality Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
Instantos
CVE-2024-42399 Aug 06, 2024
Soft AP daemon PAPI DoS: Unauthenticated exploitation Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
Instantos
CVE-2024-42393 Aug 06, 2024
Unauthenticated RCE in Soft AP Daemon Service (CVE-2024-42393) There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Instantos
CVE-2024-42396 Aug 06, 2024
Unauthenticated DoS in AP Cert Mgmt Daemon via PAPI Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
Instantos
CVE-2024-42397 Aug 06, 2024
Cisco AP Certificate Management Daemon DoS via PAPI Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
Instantos
CVE-2024-42394 Aug 06, 2024
Unauth RCE via Soft AP Daemon Service There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Instantos
CVE-2024-42395 Aug 06, 2024
CVE-2024-42395: AP Cert Mgmt Service Unauth RCE There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Instantos
CVE-2024-41911 Aug 06, 2024
Poly Clariti Manager FW <=10.10.2.2 XSS via unescaped input on page rendering A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.
Poly Clariti Manager Firmware
CVE-2024-41910 Aug 06, 2024
Poly Clariti Manager XSS Vulnerable Firmware <=10.10.2.2 A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.
Poly Clariti Manager Firmware
CVE-2024-41913 Aug 06, 2024
Poly Clariti Manager Firmware <10.10.2.2: Unsanitized User Input A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.
Poly Clariti Manager Firmware
CVE-2024-22442 Jul 16, 2024
Authentication Bypass via Remote Exploit The vulnerability could be remotely exploited to bypass authentication.
3par Service Processor Firmware
CVE-2024-6147 Jun 20, 2024
Poly Plantronics Hub LPE via Symlink Deletion in Spokes Update Service Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271.
Poly Plantronics Hub
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.