NVD disclosure day

Published threat advisories for March 27, 2026

CVE advisoryCRITICAL

CVE-2026-33943

Happy DOM Code Injection Vulnerability Enables Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A code injection vulnerability in the Happy DOM JavaScript library allows for remote code execution by injecting arbitrary JavaScript expressions into module scripts. This occurs because the `ECMAScriptModuleCompiler` directly interpolates unsanitized content into generated code. Systems processing specially crafted mo

CVE advisoryCRITICAL

CVE-2026-33937

Handlebars Compile Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Handlebars templating technology could allow an attacker to execute arbitrary JavaScript on affected servers by supplying a crafted Abstract Syntax Tree (AST) to the `compile()` function. This could lead to remote code execution if the server processes unsanitized input. It is uncertain if your e

CVE advisoryCRITICAL

CVE-2026-33896

Forge Certificate Validation Bypass Leads to Trust Issues.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Forge JavaScript library may allow improperly signed certificates to be accepted as valid, potentially undermining trust in systems that rely on certificate validation for security. Forge is used to implement Transport Layer Security. The library fails to enforce certain certificate requirements,

CVE advisoryCRITICAL

CVE-2026-28368

Undertow Request Smuggling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in Undertow allows attackers to smuggle requests by exploiting differences in header name parsing between Undertow and upstream proxies, potentially bypassing security controls and gaining unauthorized access to resources. This vulnerability impacts external-facing web services and applications, making it import

CVE advisoryCRITICAL

CVE-2026-33758

OpenBao OIDC XSS via Authentication Error Description

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenBao installations with enabled OIDC/JWT authentication and specific role configurations are vulnerable to cross-site scripting. This flaw, present before version 2.5.2, could allow an attacker to steal a victim's web UI authentication token via a crafted error message on a failed login. The vendor has addressed thi

CVE advisoryCRITICAL

CVE-2026-27876

Grafana Enterprise RCE via SQL Expressions and Plugin Chained Attack.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A chained attack involving SQL Expressions and a Grafana Enterprise plugin can lead to remote code execution. This vulnerability impacts Grafana instances with the `sqlExpressions` feature enabled. An attacker could potentially run arbitrary code on affected systems, posing a risk to service integrity and availability.

CVE advisoryCRITICAL

CVE-2026-33728

Datadog Java Agent RMI Deserialization Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The `dd-trace-java` component has a vulnerability that could allow unauthorized code execution. This affects organizations using Java 16 or earlier with specific network configurations. Attackers could gain control of systems and compromise data. Action is advised to mitigate risk.

CVE advisoryCRITICAL

CVE-2026-33701

OpenTelemetry Java RMI Deserialization Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenTelemetry Java instrumentation has a vulnerability where an attacker with network access to a JMX or RMI port on an older JDK (16 or earlier) could achieve remote code execution. This occurs when the instrumentation's RMI feature deserializes unfiltered incoming data, impacting system integrity and confidentiality.