HP patched three high-severity vulnerabilities in HP Easy Start for macOS that affect versions earlier than 2.16.7.260722. The most severe, CVE-2026-12554 (CVSS 8.5), affects an outdated OSPFTP component and could allow a network attacker to interfere with software downloads when the application falls back to FTP. CVE-2026-12556 (CVSS 7.7) globally relaxes macOS App Transport Security, permitting insecure HTTP connections and raising the risk of cleartext or tampered software delivery.
A separate local privilege-escalation issue, CVE-2026-12555 (CVSS 7.7), involves predictable temporary-file paths used by the privileged HP Uninstaller. A local attacker could exploit symbolic links to cause limited modification of files with elevated privileges. HP has released version 2.16.7.260722 to remediate all three issues; organizations should update affected macOS endpoints and review whether older HP Easy Start installations remain deployed.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
HP published a security advisory for CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, affecting HP Easy Start for macOS versions earlier than 2.16.7.260722. The flaws involve FTP fallback in an outdated download component, predictable privileged uninstaller temporary paths, and relaxed App Transport Security settings.
Nir Yehoshua of Cipher Security Labs published technical details for the three HP Easy Start macOS flaws, including a proof of concept showing root-appended HP log data can be redirected through predictable temporary-file symlinks. The disclosure also documented that version 2.16.7 removes the affected legacy components and uses a signed-client-restricted helper that validates package SHA-256 from an open file descriptor before installation.
HP released HP Easy Start for macOS version 2.16.7.260722 to remediate all three vulnerabilities. The patched release reportedly removes the OSPFTP component and vulnerable uninstaller paths and tightens transport-security configuration.
Nir Yehoshua of Cipher Security Labs identified CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556 while assessing HP Easy Start for macOS version 2.16.0 build 251010, and reported the issues to HP.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcereddit.com
Open sourcecve.org
Open sourcecve.org
Open sourceciphersecuritylabs.com
Open sourceciphersecuritylabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.