Halo Threat Intelligence

Internet-Facing CVE Threat Intelligence

Prioritize newly modified vulnerabilities with Halo Surface Signal, known-exploit context, and remediation-focused advisories.

Latest threat feed

Top 10 advisories with Halo Signal 5 or CISA KEV status, ordered by the latest NVD modification.

CVE advisoryKnown Exploit

CVE-2026-64849

MLflow Webhooks SSRF to Internal Services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An open-source AI engineering platform has a vulnerability where an unauthenticated request to its webhook test endpoint can be redirected to internal or cloud metadata services, potentially exposing sensitive information. This issue allows an attacker to reach internal services by exploiting improper URL validation af

• CISA KEV

CVE advisoryKnown Exploit

CVE-2010-0738

Red Hat JBoss EAP JMX-Console Method Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The JBoss Enterprise Application Platform's JMX-Console web application has an access control flaw, allowing unauthorized access to its GET handler. This could expose sensitive operations or data to attackers. The U.S. CISA has identified this vulnerability as actively exploited in ransomware campaigns. Organizations s

• CISA KEV

CVE advisoryKnown Exploit

CVE-2010-2861

Adobe ColdFusion File Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Directory traversal vulnerabilities in Adobe ColdFusion's administrator console allow attackers to read arbitrary files. This affects organizations using the affected software, presenting a business risk of unauthorized data exposure. Exploitation can occur without authentication. <ctrl100>

• CISA KEV

CVE advisoryKnown Exploit

CVE-2013-0431

Oracle JRE Sandbox Bypass Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Java Runtime Environment could allow attackers to bypass security protections, potentially impacting systems that use these components and enabling unauthorized access. This poses a moderate business risk, requiring organizations to identify affected assets and apply vendor updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-27924

Zimbra Collaboration: Arbitrary Command Injection Risk

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Zimbra Collaboration Suite is affected by a command injection vulnerability that allows unauthenticated attackers to overwrite cached data. This presents a business risk of unauthorized data modification and service disruption. Organizations should prioritize remediation to mitigate potential impacts.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2018-7602

Drupal Core Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Drupal core enables remote code execution, potentially allowing attackers to compromise websites. This issue is actively exploited, posing a business risk. Organizations using affected Drupal versions should prioritize mitigation.Drupal core systems contain a vulnerability that allows for remote code

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-30333

UnRAR Directory Traversal Vulnerability Affects File Integrity

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A directory traversal vulnerability in RARLAB UnRAR for Linux and UNIX systems allows unauthorized file writing during archive extraction. This can lead to the modification or creation of sensitive files, posing a risk to system integrity and data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-12812

FortiOS SSL VPN Authentication Bypass Risk.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper authentication vulnerability in FortiOS SSL VPN allows users to bypass multi-factor authentication by altering username case, potentially leading to unauthorized access and data compromise. This affects organizations using the affected SSL VPN components and presents a significant business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-21975

VMware vRealize Operations Manager API Credential Theft Risk.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Server-Side Request Forgery vulnerability in the VMware vRealize Operations Manager API allows a malicious actor with network access to steal administrative credentials. This poses a business risk of unauthorized access and potential data compromise.

• CISA KEV