https://www.securityweek.com/xerox-versalink-printer-vulnerabilities-enable-lateral-movement/
A critical security flaw in the Versalink allowed lateral movement in an org, and access to Active Directory.
This is how seriously XRX handled it:
"The two issues were reported to Xerox in March 2024. Fixes for them were rolled out at the end of January 2025, in the form of service pack updates for the VersaLink C7020, 7025, and 7030 series multifunction printers. "
XRX had a dangerous, active exploit on the Versalink and didn't patch it for 10 MONTHS?
Who the fu-k would trust XRX in their data center, or any mission-critical ops, if they can't patch a server in under 10 months?