NVD disclosure day

Published threat advisories for March 10, 2026

CVE advisoryCRITICAL

CVE-2026-28806

Nerves Hub lets attackers control devices from other companies disrupting services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Nerves Hub has a critical flaw allowing attackers to control devices outside their company, potentially disrupting services and firmware updates. This is serious because it affects device management and could lead to full device compromise.

CVE advisoryCRITICAL

CVE-2026-28292

Simple Git Remote Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the `simple-git` Node.js library allows remote code execution, potentially enabling attackers to control the host system. This issue bypasses prior security fixes and could be exploited through specially crafted input. Confirmation of `simple-git` usage within the environment is necessary to

CVE advisoryCRITICAL

CVE-2026-3843

BUK TS-G Gas Station Automation System SQL Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability in a gas station automation system may allow remote attackers to execute arbitrary SQL commands and potentially achieve remote code execution by sending specially crafted HTTP POST requests. This is a critical issue as it could compromise system configuration data and lead to unauthorized

CVE advisoryCRITICAL

CVE-2025-56422

LimeSurvey Deserialization Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in LimeSurvey allows remote attackers to execute arbitrary code on the server. This could lead to compromised server integrity if the application processes untrusted serialized data. Security-aware leaders should confirm if their organization uses this survey platform and assess its expo