NVD disclosure day

Published threat advisories for April 2, 2026

CVE advisoryCRITICAL

CVE-2025-15620

HiOS Switch Web Interface Reboot Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A denial-of-service vulnerability in the HiOS Switch Platform's web interface allows unauthenticated remote attackers to reboot devices via crafted HTTP requests, causing service disruption. This could impact network availability if reachable. Confirmation of affected devices and exposure is recommended.

CVE advisoryCRITICAL

CVE-2026-35053

OneUptime Worker API Unauthenticated Workflow Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability exists in the OneUptime Worker service, allowing attackers to trigger arbitrary workflows by guessing or obtaining a workflow ID. This could result in JavaScript code execution, notification abuse, or data manipulation. This issue affects OneUptime deployments prior to version 10.0.42.

CVE advisoryCRITICAL

CVE-2026-34838

Group-Office Insecure Deserialization Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Group-Office's AbstractSettingsCollection model allows an authenticated attacker to execute arbitrary code on the server by injecting serialized data. This insecure deserialization could lead to arbitrary file writes, potentially impacting data integrity and availability. This is critical for confirm

CVE advisoryCRITICAL

CVE-2024-14034

Hirschmann HiEOS Authentication Bypass Via HTTP Management Module

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Hirschmann HiEOS devices contain an authentication bypass vulnerability in their HTTP(S) management module. Unauthenticated remote attackers can gain administrative access by sending specially crafted requests, potentially leading to unauthorized configuration changes or firmware modification. This is a concern if the

CVE advisoryCRITICAL

CVE-2026-34759

OneUptime Notification API Unauthenticated Access Leading to Twilio Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Unauthenticated notification API endpoints in the OneUptime monitoring platform, reachable via an Nginx proxy, can be exploited alongside a projectId leak. This allows an attacker to potentially purchase phone numbers and delete existing alerting numbers from a victim's Twilio account.

CVE advisoryCRITICAL

CVE-2026-34877

Mbed TLS Session Structure Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Mbed TLS allows an attacker to corrupt memory and potentially execute arbitrary code by manipulating serialized SSL context or session data, due to improper handling of privileged APIs. This vulnerability could affect the integrity and availability of services using the Mbed TLS library. It is uncertain if Mb

CVE advisoryCRITICAL

CVE-2026-33950

Signal K Server Admin Role Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A privilege escalation vulnerability exists in Signal K Server, allowing unauthenticated attackers to gain full administrator access. This could lead to unauthorized modification of sensitive vessel routing data and server configurations. Understanding the presence and network reachability of this server application is

CVE advisoryCRITICAL

CVE-2026-25212

Percona PMM `pmm-admin` Authenticated OS Command Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An issue in Percona Monitoring and Management allows an attacker with administrative rights to execute shell commands on the operating system by abusing the "Add data source" feature. This occurs because an internal database user retains excessive privileges. This vulnerability could potentially impact the integrity an

CVE advisoryCRITICAL

CVE-2026-33746

Convoy Panel JWT Signature Verification Flaw Allows Authentication Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Convoy, a server management panel, where a failure to verify JWT token signatures allows attackers to forge tokens and impersonate any user. This affects the single sign-on authentication flow, potentially granting unauthorized access to hosted environments. Teams responsible for appl

CVE advisoryCRITICAL

CVE-2026-35002

Agno Arbitrary Code Execution via Field Type Manipulation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Agno software permits arbitrary code execution when an attacker manipulates the `field_type` parameter in a function call. This flaw, present in versions prior to 2.3.24, could allow remote code execution by influencing model execution. Understanding Agno's presence and exposure within the e