NVD disclosure day

Published threat advisories for January 13, 2026

CVE advisoryKnown Exploit

CVE-2026-20963

Microsoft SharePoint Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Microsoft SharePoint allows unauthorized attackers to execute code remotely over a network. This issue arises from the deserialization of untrusted data. Affected organizations face business risks including system compromise and potential data impact.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-20805

Microsoft Windows Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Desktop Window Manager allows local attackers to disclose sensitive information. This could lead to unauthorized access to confidential data, posing a business risk. Organizations should identify and update affected Windows systems.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-65783

Hub Arbitrary File Upload Vulnerability Allows Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Hubert Hub application's file upload functionality permits attackers to execute arbitrary code by uploading a malicious PDF. This could compromise system integrity and confidentiality. It's important to understand how this software is deployed to assess potential risks.

CVE advisoryCRITICAL

CVE-2026-0881

Firefox and Thunderbird Sandbox Escape Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Messaging System component of Mozilla's Firefox and Thunderbird, allowing for a sandbox escape. This could potentially enable attackers to gain broader system access after a user interacts with specially crafted content. This issue requires attention to ensure system integrity and

CVE advisoryCRITICAL

CVE-2026-0879

Firefox Thunderbird Graphics Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in the Graphics component of Firefox and Thunderbird. If exploited, this could allow attackers to bypass application security boundaries, potentially leading to unauthorized code execution. Leaders should confirm the relevance of this issue within their environment.