← Vulnerability feed

Vulnerability record · CVE-2023-26066 · published 10 April 2023

CVE-2023-26066: Lexmark cxtpc firmware vulnerability

Lexmark · Cxtpc Firmware

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

9.8 CVSS 3.1 Critical EPSS 0.71% · top 48.4% CWE-129 · CWE-129
9.8CVSS 3.1 base score
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
26Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26066 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26063Lexmark cxtpc firmware type confusion vulnerabilityCertain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.EPSS 0.71%9.8CVE-2023-26064Lexmark cxtpc firmware out-of-bounds write vulnerabilityCertain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.EPSS 0.71%9.8CVE-2023-26065Lexmark cxtpc firmware integer overflow vulnerabilityCertain Lexmark devices through 2023-02-19 have an Integer Overflow.EPSS 0.71%9.8CVE-2023-26068Lexmark cxtpc firmware improper input validation vulnerabilityCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).EPSS 12%9.8CVE-2023-26069Lexmark cxtpc firmware improper input validation vulnerabilityCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).EPSS 0.71%9.8CVE-2023-26070Lexmark cxtpc firmware improper input validation vulnerabilityCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).EPSS 0.71%8.1CVE-2023-26067Lexmark cxtpc firmware improper input validation vulnerabilityCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).EPSS 38%8.8CVE-2022-48503Apple WebKit bounds check flaw allows code execution via web contentApple fixed an insufficient bounds-checking issue in WebKit across Safari, iOS, iPadOS, macOS, tvOS and watchOS. Processing malicious web content can…KEVEPSS 3.2%analysed

Source: NIST National Vulnerability Database (record CVE-2023-26066), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.