NVD disclosure day

Published threat advisories for January 28, 2026

CVE advisoryCRITICAL

CVE-2025-61140

JSONPath Prototype Pollution Vulnerability in dchester jsonpath

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A prototype pollution vulnerability exists in the jsonpath library, which could allow an attacker to modify application data. If the library processes untrusted input, this could lead to unexpected behavior or data exposure, making it important to confirm its relevance and exposure in your environment.A prototype pollu

CVE advisoryKnown Exploit

CVE-2025-40551

SolarWinds Web Help Desk Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SolarWinds Web Help Desk is affected by a vulnerability allowing unauthenticated remote code execution. This could enable attackers to run commands on host systems, posing a significant business risk. Organizations should address this threat promptly.

• CISA KEV