NVD disclosure day

Published threat advisories for February 17, 2026

CVE advisoryKnown Exploit

CVE-2026-22769

Dell RecoverPoint for Virtual Machines could allow an external attacker to take full system control.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Dell RecoverPoint for Virtual Machines contains a security flaw that allows an external attacker to gain full administrative control over the system. This could lead to unauthorized access to your critical backup data and provide long-term access to your data protection environment.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-26220

LightLLM Unauthenticated Remote Code Execution via Unsafe Deserialization in Prefill-Decode Mode.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

LightLLM's prefill-decode disaggregation mode contains a critical vulnerability allowing unauthenticated remote code execution. An attacker reaching the PD master node can send malicious data via WebSocket, leading to arbitrary code execution due to unsafe deserialization. This could impact service availability and int