NVD disclosure day

Published threat advisories for February 20, 2026

CVE advisoryCRITICAL

CVE-2026-25896

fast-xml-parser DOCTYPE entity name wildcard bypass allows XSS.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The fast-xml-parser library is vulnerable to a cross-site scripting (XSS) flaw that can be exploited by manipulating DOCTYPE entity names. An attacker could craft malicious XML to bypass entity encoding, potentially leading to script execution if the parsed output is rendered without sanitization. This issue affects us

CVE advisoryCRITICAL

CVE-2025-10970

Kolay Software Talentics Blind SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability affects Talentics software, allowing unauthenticated attackers to potentially access and manipulate sensitive data by injecting malicious SQL commands. The full impact is uncertain due to the vendor's lack of response. Readers should confirm if Talentics is in use and assess poten