NVD disclosure day

Published threat advisories for March 13, 2026

CVE advisoryKnown Exploit

CVE-2026-3910

Google Chrome could allow an external attacker to run malicious code on user devices.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can compromise Google Chrome and Chromium-based browsers by luring users to a malicious website. This vulnerability allows the attacker to run unauthorized code on user devices, potentially leading to credential theft and unauthorized access to sensitive company data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-3909

Google Chrome could allow an external attacker to run malicious code via a web page.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can compromise a computer and access sensitive data by tricking a user into visiting a malicious website in Google Chrome. This could allow them to run unauthorized code, leading to a full system compromise.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-32304

Locutus create_function Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Locutus JavaScript library allows for arbitrary code execution due to unsanitized parameters passed to its `create_function` feature. This could permit attackers to run malicious code if the library is used in an application. Technical readers and security-aware leaders should confirm re

CVE advisoryCRITICAL

CVE-2026-31806

FreeRDP Heap Buffer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in FreeRDP, a Remote Desktop Protocol implementation, allows a malicious RDP server to send crafted commands that may cause a heap buffer overflow, potentially overwriting adjacent memory. This could affect the stability or security of the FreeRDP client. Uncertainty exists regarding how FreeRDP is depl