A critical vulnerability in HP Linux Imaging and Printing (HPLIP), tracked as CVE-2026-14544, allows unauthenticated remote attackers to trigger arbitrary code execution, privilege escalation, denial of service, or memory corruption by sending specially crafted print data to the hpcups processing path. The bug is an integer overflow (CWE-190) and has been rated CVSS 9.8. Researchers and downstream reporting described it as an incomplete fix for the earlier CVE-2026-8631, meaning prior remediation did not fully eliminate the underlying issue.
The flaw affects HPLIP versions prior to 3.26.4 and has broad exposure because HPLIP is widely deployed on Linux systems that support HP printers. Upstream reportedly fixed the issue in 3.26.4, while Linux vendors including Ubuntu, Debian, SUSE/openSUSE, Oracle Linux, and Red Hat have identified affected products or begun issuing and backporting updates; Red Hat said RHEL 8, 9, and 10 are affected, while RHEL 6 and 7 are not. Until patches are fully available across distributions, defenders have been urged to apply vendor security updates as they are released, restrict network exposure to printing services such as CUPS, isolate print servers, monitor print activity, and remove HPLIP where it is not required.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reports that Red Hat confirmed RHEL 8, 9, and 10 are affected by CVE-2026-14544, while RHEL 6 and 7 are not. The same report says no official patches were yet available for affected Red Hat versions at disclosure time.
According to ThreatAft, Linux distributions including Ubuntu, Debian, SUSE/openSUSE, and Oracle Linux are issuing or backporting fixes for CVE-2026-14544. This reflects downstream vendor response following the upstream fix.
ThreatAft reports that upstream addressed CVE-2026-14544 in HPLIP version 3.26.4. The flaw affects versions prior to 3.26.4 and can enable remote privilege escalation or arbitrary code execution through the hpcups print-processing path.
The sources state that CVE-2026-14544 is an incomplete fix bypass for the earlier HPLIP vulnerability CVE-2026-8631, meaning prior remediation did not fully address the underlying issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.