NVD disclosure day

Published threat advisories for January 23, 2026

CVE advisoryCRITICAL

CVE-2025-52025

Aptsys gemscms backend SQL Injection in GetServiceByRestaurantID

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An SQL injection vulnerability in the Aptsys gemscms POS Platform backend's GetServiceByRestaurantID endpoint allows attackers to execute arbitrary SQL code by submitting crafted input. This could lead to unauthorized access or modification of data. Confirm if your systems use this platform and are exposed to this risk

CVE advisoryCRITICAL

CVE-2025-52024

Aptsys POS Platform API Testing Tools Exposed to Unauthenticated Users

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Aptsys POS Platform Web Services module allows unauthenticated users to access internal API testing tools, potentially enabling external actors to discover and execute critical functions such as transaction retrieval and credit adjustments. This lack of authentication and validation could lead to

CVE advisoryKnown Exploit

CVE-2026-24423

SmarterMail ConnectToHub API Unauthenticated Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated remote code execution vulnerability exists in SmarterMail's ConnectToHub API. Attackers can direct the application to a malicious server, leading to the execution of operating system commands. This impacts organizations by potentially compromising systems and data.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-4320

Sufirmam Authentication Bypass and Weak Password Recovery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Sufirmam software allows attackers to bypass authentication and recover user passwords through a weak recovery mechanism. This could lead to unauthorized account access and control if the software is reachable. The vendor has not responded to the disclosure of this critical issue.

CVE advisoryCRITICAL

CVE-2025-4319

Sufirmam Authentication and Password Recovery Vulnerabilities

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Sufirmam's authentication and password recovery mechanisms allows for brute-force attacks and password exploitation. This could lead to unauthorized access to user accounts and potentially sensitive information when the system is reachable over a network. The vendor has not responded to inqu