basicsecurity.net
Proof, not just disclosure.
Threats / Xerox FreeFlow Core / CVE-2025-8356
CVE-2025-8356 · EUVD no mirror located8 · GCVE no mirror located9 Verified 2026-08-11

Xerox FreeFlow Core path traversal to unauthenticated RCE

An unauthenticated attacker abuses a path-traversal flaw in Xerox FreeFlow Core's job-message handling to write files outside the upload directory, plant a webshell, and run arbitrary commands on the server. Horizon3 discovered it and NodeZero proved it exploitable before it reached the CISA KEV catalog.

Verdict

Lab-proven exploitable, ahead of the catalog.

Horizon3 discovered this flaw, reported it to Xerox, and NodeZero can prove full unauthenticated remote code execution against a vulnerable FreeFlow Core. A public proof-of-concept exists and the fix ships in 8.0.5. It is not yet on the CISA KEV catalog and no confirmed in-the-wild campaign is attributed, so this is a lab-proof coverage lead we surface early, not a known-ransomware today-item. If you run an exposed, unpatched FreeFlow Core, patch to 8.0.5 now.

CISA KEV No · not listed as of 2026-08-113Horizon3 proven Yes · NodeZero proven-exploitable weakness4EPSS ~0.15 · 96th percentile (verify live)7Exploit Public PoC4CVSS 9.8 Critical1
01

Is it exploitable?

— the evidence, ranked above the score
Proven exploitable (Horizon3 NodeZero)
Horizon3.ai researcher Jimi Sebree discovered the flaw and detailed the path-traversal-to-RCE chain in FreeFlow Core's processIncomingRQEMessage handling; NodeZero shipped a Rapid Response card in the 2025.08 release to assess exposure. This is a proven weakness, not a theoretical scanner finding.We cite the existence of Horizon3's proof and public analysis; we do not host or redistribute payloads.
Not on CISA KEV (coverage lead)
As of 2026-08-11 this CVE — and every Xerox CVE — is absent from the CISA Known Exploited Vulnerabilities catalog. We surface it early on the strength of Horizon3's proof, ahead of the catalog, rather than waiting for KEV to catch up.This is a coverage lead, not a KEV removal. Re-check the KEV catalog at the cited source for the current listing.
CISA KEV ↗Confirmed
Exploit available
A public proof-of-concept and technical write-up demonstrate unauthenticated file write and webshell placement leading to remote code execution.
Horizon3 ↗Confirmed
Probability (EPSS)
EPSS around 0.15 with a ~96th-percentile ranking as of the snapshot date — elevated likelihood of exploitation activity.EPSS is a daily-changing model output — we cite the source rather than freeze a number. Open the source for today's value.
Affected / fixed
FreeFlow Core 8.0.4 is affected; Xerox fixes both CVE-2025-8356 and CVE-2025-8355 in FreeFlow Core 8.0.5 per Security Bulletin XRX25-013. Exact affected build and remediation in the vendor bulletin and NVD.
02

Who’s exploiting it?

— attribution turns risk into urgency
Attribution not established

No confirmed (advisory-backed) threat-actor attribution is established for this record. Absence of a named actor is not absence of compromise — see Coverage & confidence.

03

Why it matters

— the attack path, told twice: adversary, then board
1

Front door — unauthenticated access narrative 1

Attacker
No credentials. I send a crafted job message to an internet-facing FreeFlow Core and use a directory-traversal path to write my file wherever I want on the server.
Business
The incident starts at your print-orchestration server itself — no phishing, no stolen password required.
2

Foothold — code execution narrative 2

Attacker
I drop a webshell into a web-accessible directory and call it back, turning file write into arbitrary command execution on the host.
Business
One exposed appliance becomes attacker-controlled compute inside your environment.
4

Data at risk — exfiltration narrative 4

Attacker
With command execution I read the documents and job data flowing through the print pipeline and pivot toward anything the host can reach.
Business
Sensitive documents in the print workflow, and lateral reach from the server, become exposure you have to account for.
04

What to do

— defensible action
  • Patch to FreeFlow Core 8.0.5, which fixes both CVE-2025-8356 and CVE-2025-8355. Per Xerox Security Bulletin XRX25-013.6
  • Take FreeFlow Core off the public internet. This is a print-orchestration back-office system; restrict it to trusted networks and hunt for unexpected files in web-accessible upload directories on any instance that was exposed while unpatched.4
Say it to the boardHorizon3 found this flaw and NodeZero can prove full remote code execution against an unpatched Xerox FreeFlow Core — with a public exploit already circulating — before it has even reached the government's known-exploited list. Patching 8.0.5 now is cheaper than the incident later.
05

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • Mechanism, CVSS 9.8, CWE mapping (NVD, CVE.org)
  • Proven exploitable + discovery attribution (Horizon3, NodeZero 2025.08 Rapid Response)
  • Fixed build 8.0.5 (Xerox Bulletin XRX25-013)
  • EPSS ranking (FIRST)
  • Coverage gaps — stated, not hidden

  • Not on CISA KEV as of 2026-08-11 — no government known-exploited confirmation; tracked as a lab-proof lead.
  • No confirmed in-the-wild exploitation or named threat actor — absence of a headline actor is honest, not an omission.
  • No EUVD / GCVE mirror located — single-authority dependency for the identifier.
  • EPSS is time-varying; we link the source rather than freeze a stale number.
  • Disclosure & credit2
    Catalogued by XeroxCNA
    Credited with finding itJimi Sebree (Horizon3.ai)finder
    Found an error? Propose a correction.

    A correction is a cited counter-claim — it must cite a source, gets reviewed by a second human, and is never auto-applied. See the correction convention and our identity npub1j7gt9ky7sfcrjn8jjee6693dkzvk4rahs0fk2suu7968dfns62zs3mqm3y.

    Corrections must cite a source.

    Paste into your Nostr client; it will sign with your key and publish.