NVD disclosure day

Published threat advisories for January 13, 2026

CVE advisoryKnown Exploit

CVE-2026-20963

Microsoft SharePoint Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Microsoft SharePoint allows unauthorized attackers to execute code remotely over a network. This issue arises from the deserialization of untrusted data. Affected organizations face business risks including system compromise and potential data impact.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-20805

Microsoft Windows Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Desktop Window Manager allows local attackers to disclose sensitive information. This could lead to unauthorized access to confidential data, posing a business risk. Organizations should identify and update affected Windows systems.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-68811

Linux Kernel RDMA Incorrect Byte Offset Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA component, involving an incorrect byte offset in memory copies, could allow for system compromise. While rated critical, its specialized use within internal networks may limit direct external reachability, though internal impact is possible.

CVE advisoryCRITICAL

CVE-2025-68809

Linux Kernel ksmbd Race Condition in File Deletion Logic

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A race condition in the Linux kernel's ksmbd component can cause inconsistent file deletion behavior, where files may not be removed as expected or could vanish while in use. This vulnerability is reachable through concurrent file operations on shared files. You should care if your organization uses Linux file sharing,

CVE advisoryCRITICAL

CVE-2025-68794

Linux Kernel iomap Read Range Calculation Flaw Leads to Incorrect Data Handling.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's iomap component can cause incorrect calculations for read ranges, potentially leading to data handling errors. This flaw impacts non-block-aligned positions and could result in too many bytes being skipped or invalid read parameters being returned. Understanding its relevance to yo

CVE advisoryCRITICAL

CVE-2025-68775

Linux Kernel Duplicate Handshake Cancellation Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's network handshake handling allows duplicate cancellation requests to cause a socket reference count underflow. This could occur during handshake timeouts and potentially lead to system instability. The issue requires specific timing and conditions, making direct exploitation less l

CVE advisoryCRITICAL

CVE-2025-65783

Hub Arbitrary File Upload Vulnerability Allows Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Hubert Hub application's file upload functionality permits attackers to execute arbitrary code by uploading a malicious PDF. This could compromise system integrity and confidentiality. It's important to understand how this software is deployed to assess potential risks.

CVE advisoryCRITICAL

CVE-2026-0881

Firefox and Thunderbird Sandbox Escape Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Messaging System component of Mozilla's Firefox and Thunderbird, allowing for a sandbox escape. This could potentially enable attackers to gain broader system access after a user interacts with specially crafted content. This issue requires attention to ensure system integrity and

CVE advisoryCRITICAL

CVE-2026-0879

Firefox Thunderbird Graphics Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in the Graphics component of Firefox and Thunderbird. If exploited, this could allow attackers to bypass application security boundaries, potentially leading to unauthorized code execution. Leaders should confirm the relevance of this issue within their environment.