Skip to content
Critical Remote Code Execution Vulnerabilities in SUSE HPLIP

Critical Remote Code Execution Vulnerabilities in SUSE HPLIP

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •Four critical vulnerabilities in SUSE HPLIP allow remote code execution and privilege escalation.
  • •CISA confirms active exploitation of these vulnerabilities in the wild.
  • •Patches are available, and immediate application is recommended for affected systems.

Multiple critical vulnerabilities in the HPLIP software for SUSE Linux have been disclosed, allowing remote code execution, privilege escalation, and denial of service. The vulnerabilities are identified as CVE-2026-91097, CVE-2026-91098, CVE-2026-91099, and CVE-2026-91100, with the first three being of high severity. CISA has confirmed that these vulnerabilities are being actively exploited. Affected systems include various versions of SUSE Linux Enterprise Server and openSUSE. Patches have been released, and users are urged to apply them immediately to mitigate risks. The vulnerabilities were published on September 16, 2026, with proof-of-concept code available since September 22, 2026. The situation is critical, and organizations are advised to check their systems for the latest updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-91097, 91098, 91099 published
Multiple vulnerabilities in HPLIP software disclosed, enabling remote code execution and other attacks.
Linuxsecurity
2026-09-16
CVE-2026-91098 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-91100 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-91099 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
First public PoC for CVE-2026-91097
Proof-of-concept code for the critical vulnerability was made publicly available.
Linuxsecurity
2026-09-24
Critical patch released for HPLIP
SUSE released an update addressing the critical vulnerabilities in HPLIP software.
Linuxsecurity
2026-09-28
Additional patches released
Further updates were released to address the vulnerabilities, emphasizing their critical nature.
Linuxsecurity
2026-09-29
CISA confirms exploitation
CISA confirmed that the vulnerabilities are being actively exploited in the wild.
Linuxsecurity

More articles in this cluster (5)

Following this threat?

Track SuSE and CVE-2026-91097 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed