❌

Reading view

There are new articles available, click to refresh the page.

Code Security Review tool

Posted by E. Kellinis on Sep 22

Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

Posted by Joe via Fulldisclosure on Sep 22

HP Advance / HP Output Central
Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file
write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084

================================================================
SUMMARY
================================================================

Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components:...

CFP No cON Name 2k26 - Palma, Mallorca - Spain

Posted by Jose Nicolas Castellano on Sep 22

No cON Name 2026 - Palma, Mallorca - Balearic Islands

************************************
*****Β  Call For PapersΒ  Β  Β  Β  ******
************************************

https://www.noconname.org/call-for-papers/

Exact place not disclosed until a few weeks before due celebration.

Β  Β  * INTRODUCTIONfulldisclosure () seclists org
The organization hasΒ  opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)

Posted by Louis Sanchez via Fulldisclosure on Sep 22

Posting this as an update rather than a first disclosure. The advisory
went public on 2026-08-04 with no vendor fix. Penpot has shipped two
releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on
2026-08-27 -- and I re-checked the code this morning: the missing
permission check is still missing in both, and in every release before
them. It was fixed on develop the day after this advisory went public.
That fix has never shipped....

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)

Posted by Raschin Tavakoli via Fulldisclosure on Sep 22

nullFaktor Security Advisory < 2026-09-10 >
===========================================================
Title: Pre-Authentication Remote Code Execution in SAP
Extended Passport (EPP) processing library
Affected Components: ICM, SAP Web Dispatcher, dialog work processes

Vulnerability: Stack based Buffer Overflow
CVE: CVE-2026-44756

Impact: Critical
CVSS 4.0 Vector:...

[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
TigerGraph Community Edition 4.2.4.

Type: Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (CWE-798)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog and
configuration tree
Authentication: unauthenticated (shipped default credentials)...

[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Teltonika RutOS 00.07.06.21.

Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the router, with command output reflected into the JSON response
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...

APPLE-SA-09-14-2026-10 Xcode 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-10 Xcode 27

Xcode 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149040.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Xcode IDE
Available for: macOS Tahoe 26.6 and later
Impact: An app may be able to access user-sensitive data
Description: A permissions issue...

APPLE-SA-09-14-2026-9 Safari 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-9 Safari 27

Safari 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149039.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Safari
Available for: macOS Sequoia and macOS Tahoe
Impact: A malicious website may be able to determine what apps a user
has installed...

APPLE-SA-09-14-2026-8 visionOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-8 visionOS 27

visionOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149038.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-7 watchOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-7 watchOS 27

watchOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149037.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Watch Series 9 and later
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-6 tvOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-6 tvOS 27

tvOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149036.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

macOS Sequoia 15.8 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149043.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Sequoia
Impact: Processing a maliciously crafted image may lead to unexpected...

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

macOS Tahoe 26.7 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149042.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image may lead to unexpected
process...

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

macOS Golden Gate 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149035.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro...

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path
without credential override (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Royal Server 5.04.50529.0.

Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250)
CVSS: 7.2...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote
escaping (8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
core-admin 1.0.164 (build 16468).

Type: Systemic shell command injection via ineffective quote escaping (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective)
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
OP5 Monitor 9.20.

Type: Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
QuantaStor 6.8.3.018.

Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT
AUTHORITY\SYSTEM (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
SmarterMail 100.0.9693 (Build 9693).

Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250)
CVSS: 7.2...
❌