NVD disclosure day

Published threat advisories for March 4, 2026

CVE advisoryCRITICAL

CVE-2026-29000

pac4j-jwt Authentication Bypass via Encrypted JWT Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass vulnerability exists in pac4j-jwt when processing encrypted JWTs, allowing remote attackers to forge tokens and impersonate users, including administrators. This occurs if an attacker possesses the server's RSA public key and can craft a malicious token that bypasses signature verificat

CVE advisoryKnown Exploit

CVE-2026-20131

Cisco firewall allows attackers to take control of your network

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can gain full administrative control over the Cisco Secure Firewall Management Center. This enables them to bypass security policies and disable defensive controls, risking unauthorized access to the network infrastructure.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-27446

Apache Artemis Core Protocol Federation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Artemis and Apache ActiveMQ Artemis allows an unauthenticated attacker to inject or exfiltrate messages by forcing a broker to connect to a rogue server. This can occur if the environment permits untrusted incoming or outgoing connections using the Core protocol, potentially impacting message