Xerox Product Security Update Advisory

Xerox Product Security Update Advisory

Overview

 

We have released a security update to fix vulnerabilities in Xerox products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-8355, CVE-2025-8356

 

FreeFlow Core Version: 8.0.4

 

 

Resolved Vulnerabilities

 

SSRF Vulnerability in FreeFlow Core by Xerox (CVE-2025-8355)
Path Traversal Vulnerability in Xerox’s FreeFlow Core (CVE-2025-8356)

 

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-8355, CVE-2025-8356

 

FreeFlow Core Version: 8.0.5

 

 

References

 

[1] Security Bulletin XRX25-013
https://securitydocs.business.xerox.com/wp-content/uploads/2025/08/Xerox-Security-Bulletin-025-013-for-Freeflow-Core-8.0.5.pdf