NVD disclosure day

Published threat advisories for February 27, 2026

CVE advisoryCRITICAL

CVE-2026-28517

openDCIM OS Command Injection via Network Map Reporting

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An OS command injection vulnerability exists in openDCIM's network map reporting feature. An attacker could execute arbitrary commands on the web server by altering a database configuration parameter, as the application does not validate this input before using it in a system command. This poses a risk if the openDCIM

CVE advisoryCRITICAL

CVE-2026-28516

openDCIM SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability exists in openDCIM's configuration update function. An authenticated user can exploit this by submitting malicious SQL code through specific handlers, enabling the execution of arbitrary SQL statements against the database. This could lead to unauthorized data access or modification.

CVE advisoryCRITICAL

CVE-2026-28515

openDCIM Installer Missing Authorization Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A missing authorization vulnerability in openDCIM's installer scripts allows authenticated users to modify LDAP configurations, potentially without credentials if `REMOTE_USER` is improperly configured. This enables unauthorized changes to application settings, impacting data center infrastructure management.

CVE advisoryCRITICAL

CVE-2025-11252

Windesk.Fm SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in Signum Technology Promotion and Training Inc.'s Windesk.Fm software could allow attackers to access and manipulate data. This issue is reachable over the network and does not require authentication. While the vendor has released a fix, understanding the potential impact on faci

CVE advisoryCRITICAL

CVE-2025-11251

Daynex E-Commerce Platform SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Dayneks E-Commerce Platform, allowing attackers to manipulate database queries through specially crafted input. This could lead to unauthorized access, modification, or deletion of sensitive data. The vendor has not responded to inquiries about this issue.