NVD disclosure day

Published threat advisories for January 21, 2026

CVE advisoryCRITICAL

CVE-2026-22807

vLLM Dynamic Module Loading Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The vLLM inference engine has a vulnerability that allows arbitrary code execution on the host during model loading if it loads code from an attacker-controlled source. This can happen before any requests are processed and does not require API access, posing a risk to systems hosting large language models.

CVE advisoryKnown Exploit

CVE-2026-20045

Cisco Unified Communications Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Cisco Unified Communications products allows unauthenticated remote attackers to execute commands on the operating system. This could lead to unauthorized access and privilege escalation, impacting communication systems. The business risk is considered Critical.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-24061

GNU Inetutils Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

GNU Inetutils telnetd has an authentication bypass vulnerability. This flaw allows unauthorized remote access by manipulating the USER environment variable. The business risk includes unauthorized system access and potential data compromise.

• CISA KEV