❌

Normal view

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

22 September 2026 at 18:32

Posted by Joe via Fulldisclosure on Sep 22

HP Advance / HP Output Central
Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file
write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084

================================================================
SUMMARY
================================================================

Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components:...

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)

22 September 2026 at 18:31

Posted by Raschin Tavakoli via Fulldisclosure on Sep 22

nullFaktor Security Advisory < 2026-09-10 >
===========================================================
Title: Pre-Authentication Remote Code Execution in SAP
Extended Passport (EPP) processing library
Affected Components: ICM, SAP Web Dispatcher, dialog work processes

Vulnerability: Stack based Buffer Overflow
CVE: CVE-2026-44756

Impact: Critical
CVSS 4.0 Vector:...

[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
TigerGraph Community Edition 4.2.4.

Type: Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (CWE-798)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog and
configuration tree
Authentication: unauthenticated (shipped default credentials)...

[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Teltonika RutOS 00.07.06.21.

Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the router, with command output reflected into the JSON response
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...

APPLE-SA-09-14-2026-10 Xcode 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-10 Xcode 27

Xcode 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149040.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Xcode IDE
Available for: macOS Tahoe 26.6 and later
Impact: An app may be able to access user-sensitive data
Description: A permissions issue...

APPLE-SA-09-14-2026-9 Safari 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-9 Safari 27

Safari 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149039.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Safari
Available for: macOS Sequoia and macOS Tahoe
Impact: A malicious website may be able to determine what apps a user
has installed...

APPLE-SA-09-14-2026-8 visionOS 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-8 visionOS 27

visionOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149038.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-7 watchOS 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-7 watchOS 27

watchOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149037.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Watch Series 9 and later
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-6 tvOS 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-6 tvOS 27

tvOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149036.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

macOS Sequoia 15.8 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149043.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Sequoia
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

macOS Tahoe 26.7 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149042.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image may lead to unexpected
process...

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

macOS Golden Gate 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149035.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro...
❌