NVD disclosure day

Published threat advisories for March 16, 2026

CVE advisoryCRITICAL

CVE-2026-4177

YAML::Syck Heap Buffer Overflow and Memory Leak Vulnerabilities

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in YAML::Syck, a Perl module for parsing YAML, which could lead to heap buffer overflows and memory corruption. Attackers can exploit this by sending crafted YAML data, potentially causing denial of service or system instability. This impacts applications that process YAML, highlighting

CVE advisoryCRITICAL

CVE-2026-27962

Authlib JWK Header Injection Allows JWT Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A JWK Header Injection vulnerability exists in Authlib, a Python library used for building OAuth and OpenID Connect servers. This issue allows unauthenticated attackers to forge arbitrary JWT tokens that pass signature verification, potentially bypassing authentication and authorization mechanisms entirely. If an affec

CVE advisoryCRITICAL

CVE-2025-62319

HCL Unica and Audience Central Boolean SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability allows attackers to insert malicious SQL code into backend queries. This could enable unauthorized access or modification of sensitive data by manipulating application input fields. It is important to determine if this vulnerability is relevant and reachable within your environment.

CVE advisoryHIGH

CVE-2026-4255

Thermalright TR-VISION HOME DLL Hijacking Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A DLL search order vulnerability in Thermalright TR-VISION HOME for Windows permits a local attacker to escalate privileges by substituting a legitimate library with a malicious DLL. This can lead to arbitrary code execution with elevated privileges if an attacker can place a crafted DLL in a user-writable directory wi

CVE advisoryCRITICAL

CVE-2016-20030

ZKTeco ZKBioSecurity User Enumeration Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ZKTeco ZKBioSecurity allows unauthenticated attackers to enumerate valid usernames by submitting partial inputs to a login script, potentially revealing legitimate user accounts. The primary concern is determining if this technology is used within our environment.

CVE advisoryCRITICAL

CVE-2016-20026

ZKTeco ZKBioSecurity Apache Tomcat Hardcoded Credentials Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

ZKTeco ZKBioSecurity software has a critical vulnerability due to hardcoded credentials in its bundled Apache Tomcat server, allowing unauthenticated attackers to access the manager application, upload malicious code, and execute arbitrary commands with system privileges. This poses a risk to the integrity and availabi

CVE advisoryCRITICAL

CVE-2016-20024

ZKTeco ZKTime.Net Privilege Escalation Via Insecure File Permissions.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An insecure file permissions vulnerability in ZKTeco ZKTime.Net allows unprivileged users to escalate privileges by replacing executable files. While this requires local access and is not network-exploitable, it could lead to unauthorized system control and compromise system integrity. Confirming relevance and exposure