NVD disclosure day

Published threat advisories for March 26, 2026

CVE advisoryCRITICAL

CVE-2026-30458

Fuel CMS Password Reset Token Exfiltration via Mail Splitting Attack.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in FuelCMS allows attackers to exfiltrate password reset tokens through a mail splitting attack. This means sensitive user data could be exposed if the affected software is in use and reachable. Determining if your organization uses this product is the initial concern.

CVE advisoryCRITICAL

CVE-2026-30457

Daylight Studio FuelCMS Dwoo Component Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Daylight Studio FuelCMS's Dwoo parser component allows for arbitrary code execution if reachable via network. Attackers can exploit this by sending crafted PHP code, potentially leading to system compromise. The primary concern is determining if your environment uses this software and if it'

CVE advisoryCRITICAL

CVE-2026-4809

Laravel package allows uploading dangerous files to take control of systems

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the Laravel-mediable package allows attackers to upload malicious code as images, potentially taking control of your systems if they handle file uploads. There is no patch available, so immediate review is needed for any applications using this package.