NVD disclosure day

Published threat advisories for January 22, 2026

CVE advisoryCRITICAL

CVE-2026-20912

Gitea Release Attachment Ownership Validation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Gitea has a vulnerability where it fails to properly validate repository ownership when linking attachments to releases. This could allow an attachment from a private repository to be linked to a release in a public repository, potentially exposing sensitive data to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-20897

Gitea Repository Ownership Validation Flaw Allows Cross-Repository LFS Lock Deletion.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Gitea allows users with write access to one repository to delete Git LFS locks from other repositories, potentially impacting code integrity. The exact business impact is still being assessed, but it's important to confirm if your organization uses Gitea and if it's exposed to this risk.

CVE advisoryCRITICAL

CVE-2025-56590

Apryse HTML2PDF InsertFromURL Command Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the Apryse HTML2PDF SDK's `InsertFromURL()` function allows for the execution of arbitrary operating system commands on a server. This command injection flaw could impact systems that use the SDK for document conversion via URL processing. It is uncertain if this function is exposed to exter

CVE advisoryKnown Exploit

CVE-2026-23760

SmarterMail Authentication Bypass Allows Administrative Compromise.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in SmarterMail's password reset API allows unauthenticated attackers to bypass authentication and reset administrator passwords, leading to full administrative control and potential operating system command execution. This poses a significant business risk, as the vulnerability is known to be exploited

• CISA KEV