NVD disclosure day

Published threat advisories for January 27, 2026

CVE advisoryKnown Exploit

CVE-2026-24858

Fortinet devices can be improperly accessed by attackers if FortiCloud SSO is enabled

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Fortinet devices with FortiCloud SSO enabled allow attackers to bypass security and access other accounts' devices. This is critical because it grants unauthorized access to network management and security functions.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-24881

GnuPG Agent Stack Overflow Vulnerability Allows Denial of Service or Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in GnuPG that can be triggered by a crafted S/MIME message, potentially causing a stack-based buffer overflow in `gpg-agent`. This could lead to denial of service or memory corruption that may allow for remote code execution. Although GnuPG is often used locally, its processing of external messag