NVD disclosure day

Published threat advisories for February 12, 2026

CVE advisoryCRITICAL

CVE-2026-26219

newbee-mall Weak Password Hashing Allows Offline Credential Recovery.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The newbee-mall application stores user passwords using unsalted MD5 hashing, which allows attackers to quickly recover plaintext credentials if password hashes are exposed. This impacts user authentication by enabling offline cracking of compromised hash data, potentially leading to unauthorized account access. Owners

CVE advisoryCRITICAL

CVE-2026-26218

Newbee-mall Default Administrator Credentials Allow Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Newbee-mall's initialization script includes default administrator accounts with predictable passwords, allowing unauthenticated attackers to gain full administrative control of the application if these credentials are not changed after database setup. This presents a significant risk for deployments that fail to secur

CVE advisoryCRITICAL

CVE-2026-26216

Crawl4AI Docker API Unauthenticated Remote Code Execution Via Hooks Parameter

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Crawl4AI Docker API contains a vulnerability that allows unauthenticated remote code execution. Attackers can exploit this by sending crafted requests to the `/crawl` endpoint, potentially leading to full server compromise, data exfiltration, and lateral movement. It is important to determine if this technology is

CVE advisoryCRITICAL

CVE-2026-26214

Galaxy FDS Android SDK TLS Hostname Verification Disabled Enables Man-in-the-Middle Attacks

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects an Android SDK that disables TLS hostname verification, allowing man-in-the-middle attackers to intercept and modify communications with cloud storage. This could expose sensitive information and credentials. The affected SDK is no longer supported by its vendor.

CVE advisoryCRITICAL

CVE-2025-14014

Smart Panel Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in NTN Information Processing Services Smart Panel software, allowing for unrestricted upload of dangerous file types. This could enable unauthorized access to system functionality and potential remote code execution, impacting system integrity. Its reachability needs confirmation to ass

CVE advisoryCRITICAL

CVE-2025-10969

Farktor E-Commerce Package Blind SQL Injection Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A SQL Injection vulnerability exists in Farktor E-Commerce Package, allowing remote attackers to execute arbitrary SQL commands. If reachable, this could expose or modify sensitive data. This issue warrants attention to protect customer information and transaction integrity.