CVE-2016-1896: Lexmark Printer Firmware

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.

Affected products

  • Lexmark Printer Firmware: up to and including cb.02.048; up to and including atl.02.048; up to and including yk.02.048; up to and including pp.02.048

Published 2016-01-27. Last modified 2026-06-17.