Halo Threat Intelligence

Internet-Facing CVE Threat Intelligence

Prioritize newly modified vulnerabilities with Halo Surface Signal, known-exploit context, and remediation-focused advisories.

Latest threat feed

Top 10 advisories with Halo Signal 5 or CISA KEV status, ordered by the latest NVD modification.

CVE advisoryCRITICAL

CVE-2026-77647

SPIP Arbitrary Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

SPIP, a content management system, has a critical vulnerability allowing unauthenticated remote code execution. This issue, related to incorrect identification of PHP code blocks and mishandling of specific characters by `var_export`, has been exploited in the wild. As SPIP is often a public-facing web application, thi

CVE advisoryCRITICAL

CVE-2026-69851

Azure Active Directory SSRF Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical server-side request forgery vulnerability exists in Azure Active Directory, potentially allowing an authorized attacker to elevate privileges over a network. This could impact system integrity by enabling unauthorized actions. Readers should care because Azure Active Directory is a core identity provider tha

CVE advisoryCRITICAL

CVE-2026-65801

Microsoft Exchange Online SSRF Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical Server-Side Request Forgery vulnerability in Microsoft Exchange Online could allow an unauthorized attacker to elevate privileges over a network. This impacts a critical, internet-facing business communication service. Confirming relevance and potential exposure within our environment is important to underst

CVE advisoryCRITICAL

CVE-2026-73257

Mongoose HTTP Desynchronization Request Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Mongoose web server and network library allows remote attackers to inject requests by sending a crafted HTTP request. This can lead to unauthorized access or modification of resources due to a desynchronization in how HTTP headers are parsed. This is relevant because Mongoose is often integrated

CVE advisoryCRITICAL

CVE-2026-60737

Oracle Web Services Manager Unauthorized Data Access Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Web Services Manager could allow an unauthenticated attacker with network access to gain unauthorized access to or modify critical data. This issue impacts Oracle Fusion Middleware and is relevant for technical readers and security-aware leaders to understand potential data compromise

CVE advisoryCRITICAL

CVE-2026-47865

VMware Avi Load Balancer Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

VMware Avi Load Balancer has an authentication bypass vulnerability. A threat actor with network access could potentially bypass the authentication mechanism to access the Avi Control plane. This could impact service availability and management capabilities.

CVE advisoryKnown Exploit

CVE-2026-64849

MLflow Webhooks SSRF to Internal Services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An open-source AI engineering platform has a vulnerability where an unauthenticated request to its webhook test endpoint can be redirected to internal or cloud metadata services, potentially exposing sensitive information. This issue allows an attacker to reach internal services by exploiting improper URL validation af

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-53424

Samly Authentication Bypass via Replay of SAML Assertions

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Samly library has an authentication bypass vulnerability that allows attackers to impersonate users by replaying captured SAML assertions. This happens because the library does not enforce the rule that each assertion should only be used once, potentially granting unauthorized access to systems.

CVE advisoryCRITICAL

CVE-2026-19586

Omada Gateway OpenVPN Server Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A pre-authentication OS command injection vulnerability exists in Omada gateways configured as OpenVPN servers due to insufficient validation of client-supplied data. An unauthenticated remote attacker could exploit this to execute arbitrary commands, potentially leading to full compromise of the affected device if the