CVE-2026-4682: HP Inc HP Deskjet 2800e All-In-One Printer Series
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities.
Affected products
- HP Inc HP Deskjet 2800e All-In-One Printer Series: before 2612A (fixed in 2612A)
- HP Inc HP Deskjet 4200 All-In-One Printer Series: before 2612A (fixed in 2612A)
- HP Inc HP Deskjet 4200e All-In-One Printer Series: before 2612A (fixed in 2612A)
- HP Inc HP Deskjet Ink Advantage 2800 All-In-One Printer Series: before 2612A (fixed in 2612A)
- HP Inc HP Deskjet Ink Advantage 4200 All-In-One Printer Series: before 2612A (fixed in 2612A)
- HP Inc HP Deskjet Ink Advantage Ultra 4900 Series: before 2612A (fixed in 2612A)
Published 2026-04-15. Last modified 2026-06-17.