NVD disclosure day

Published threat advisories for January 8, 2026

CVE advisoryCRITICAL

CVE-2025-59469

Backup Operator Privilege Escalation in Veeam Backup & Replication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Veeam Backup & Replication allows an authenticated backup operator to write files as root. This could potentially lead to unauthorized system modifications or data overwrites, affecting system integrity. It is uncertain if the affected software and versions are in use within the environment.

CVE advisoryCRITICAL

CVE-2025-59468

Veeam Backup & Replication Remote Code Execution via Malicious Password

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Veeam Backup & Replication allows a Backup Administrator to achieve remote code execution as the `postgres` user by supplying a malicious password parameter. This could potentially compromise the backup system and its data. The issue is relevant because privileged access to the backup system

CVE advisoryCRITICAL

CVE-2025-67924

Corpkit Theme Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Corpkit theme allows authenticated users to upload a web shell, potentially enabling server control. This could lead to unauthorized code execution if the theme is used and its upload functionality is reachable. Confirming the presence and external exposure of this theme is crucial.

CVE advisoryCRITICAL

CVE-2025-67911

Tribulant Newsletters Lite Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical deserialization vulnerability in Tribulant Software Newsletters Lite allows object injection, potentially enabling an attacker to execute arbitrary code when processing untrusted data. This could impact system integrity and availability. The relevance and exposure to your environment need to be confirmed.

CVE advisoryCRITICAL

CVE-2025-23993

Felan Framework SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Felan Framework, potentially allowing unauthorized data access or manipulation via network requests. This issue impacts applications using versions up to and including 1.1.3. Owners of affected applications should identify and assess instances for external exposure a