Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Conclusion & alert: CVE-2023-26068 is rated High Risk (75.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 81.34%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.85% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-28 | 79.49% | 81.34% | +1.85% |
| 2 | 2026-04-11 | 79.84% | 79.49% | -0.35% |
| 3 | 2026-03-07 | — | 79.84% | — |
Full EPSS history (29 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lexmark | cxtpc_firmware | < cxtpc.081.232 | cpe:2.3:o:lexmark:cxtpc_firmware:*:*:*:*:*:*:*:* |
| lexmark | cstpc_firmware | < cstpc.081.232 | cpe:2.3:o:lexmark:cstpc_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxtct_firmware | < mxtct.081.232 | cpe:2.3:o:lexmark:mxtct_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxtpm_firmware | < mxtpm.081.232 | cpe:2.3:o:lexmark:mxtpm_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxtmm_firmware | < cxtmm.081.232 | cpe:2.3:o:lexmark:cxtmm_firmware:*:*:*:*:*:*:*:* |
| lexmark | mslsg_firmware | < mslsg.081.232 | cpe:2.3:o:lexmark:mslsg_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxlsg_firmware | < mxlsg.081.232 | cpe:2.3:o:lexmark:mxlsg_firmware:*:*:*:*:*:*:*:* |
| lexmark | mslbd_firmware | < mslbd.081.232 | cpe:2.3:o:lexmark:mslbd_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxlbd_firmware | < mxlbd.081.232 | cpe:2.3:o:lexmark:mxlbd_firmware:*:*:*:*:*:*:*:* |
| lexmark | msngm_firmware | < msngm.081.232 | cpe:2.3:o:lexmark:msngm_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxngm_firmware | < mxngm.081.232 | cpe:2.3:o:lexmark:mxngm_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxtgm_firmware | < mxtgm.081.232 | cpe:2.3:o:lexmark:mxtgm_firmware:*:*:*:*:*:*:*:* |
| lexmark | msngw_firmware | < msngw.081.232 | cpe:2.3:o:lexmark:msngw_firmware:*:*:*:*:*:*:*:* |
| lexmark | mstgw_firmware | < mstgw.081.232 | cpe:2.3:o:lexmark:mstgw_firmware:*:*:*:*:*:*:*:* |
| lexmark | mxtgw_firmware | < mxtgw.081.232 | cpe:2.3:o:lexmark:mxtgw_firmware:*:*:*:*:*:*:*:* |
| lexmark | cslbn_firmware | < cslbn.081.232 | cpe:2.3:o:lexmark:cslbn_firmware:*:*:*:*:*:*:*:* |
| lexmark | cslbl_firmware | < cslbl.081.232 | cpe:2.3:o:lexmark:cslbl_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxlbn_firmware | < cxlbn.081.232 | cpe:2.3:o:lexmark:cxlbn_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxlbl_firmware | < cxlbl.081.232 | cpe:2.3:o:lexmark:cxlbl_firmware:*:*:*:*:*:*:*:* |
| lexmark | csnzj_firmware | < csnzj.081.232 | cpe:2.3:o:lexmark:csnzj_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxtzj_firmware | < cxtzj.081.232 | cpe:2.3:o:lexmark:cxtzj_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxnzj_firmware | < cxnzj.081.232 | cpe:2.3:o:lexmark:cxnzj_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxtpp_firmware | < cxtpp.081.233 | cpe:2.3:o:lexmark:cxtpp_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxtpp_firmware | < cstpp.081.233 | cpe:2.3:o:lexmark:cxtpp_firmware:*:*:*:*:*:*:*:* |
| lexmark | cstat_firmware | < cstat.081.233 | cpe:2.3:o:lexmark:cstat_firmware:*:*:*:*:*:*:*:* |
| lexmark | cxtat_firmware | < cxtat.081.233 | cpe:2.3:o:lexmark:cxtat_firmware:*:*:*:*:*:*:*:* |
| lexmark | cstmh_firmware | < cstmh.081.233 | cpe:2.3:o:lexmark:cstmh_firmware:*:*:*:*:*:*:*:* |