NVD disclosure day

Published threat advisories for April 3, 2026

CVE advisoryCRITICAL

CVE-2026-34953

PraisonAI OAuthManager Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in PraisonAI's token validation allows unauthenticated access to its agent tools and capabilities by sending arbitrary bearer tokens. This could permit unauthorized control over system functionalities. The issue has been patched in version 4.5.97.

CVE advisoryCRITICAL

CVE-2026-34938

PraisonAI Agents Command Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in PraisonAI agents, allowing for arbitrary operating system command execution through a sandbox bypass. This issue could lead to a complete compromise of the host system if the affected software is reachable. Teams should confirm if this software is deployed and relevant to their enviro

CVE advisoryCRITICAL

CVE-2026-34935

PraisonAI CLI Argument Vulnerability Allows OS Command Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in PraisonAI allows arbitrary OS command execution due to improper handling of CLI arguments. This could lead to system compromise and data exposure if the affected software is reachable. Security leaders should confirm the relevance and exposure of PraisonAI instances.

CVE advisoryCRITICAL

CVE-2026-34934

PraisonAI SQL Injection Vulnerability Allows Full Database Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in PraisonAI allows attackers to execute arbitrary SQL commands, potentially leading to full database access. This occurs when the system constructs raw SQL queries using unescaped thread IDs, enabling an attacker to inject malicious payloads. Users should ensure their PraisonAI installati

CVE advisoryCRITICAL

CVE-2026-34612

Kestra SQL Injection Leading to Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability in the Kestra orchestration platform can allow an authenticated user to execute arbitrary OS commands by visiting a crafted link. This occurs in the "GET /api/v1/main/flows/search" endpoint and leverages PostgreSQL's `COPY ... TO PROGRAM ...` to run commands on the host system. This issue

CVE advisoryCRITICAL

CVE-2021-4477

Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A firewall bypass vulnerability exists in Hirschmann HiLCOS OpenBAT and BAT450 products, potentially allowing traffic from VPN connections to circumvent security rules. This could expose network communications if these devices are in use and reachable. Uncertainty remains regarding specific product deployments and the

CVE advisoryCRITICAL

CVE-2018-25236

Hirschmann HiOS and HiSecOS HTTP(S) Management Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in the HTTP(S) management module of Hirschmann HiOS and HiSecOS products, allowing unauthenticated remote attackers to gain administrative access by crafting special HTTP requests. This could lead to unauthorized control over network services.

CVE advisoryCRITICAL

CVE-2017-20236

ProSoft ICX35-HWC Command Injection via Web Interface

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in ProSoft Technology cellular gateways allowing remote attackers to inject and execute system commands via the web interface. This can lead to root privilege escalation and arbitrary command execution on the device. Confirm if these gateways are in use and exposed to the network.A vulnerability

CVE advisoryCRITICAL

CVE-2017-20235

ProSoft ICX35-HWC Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

ProSoft Technology cellular gateways contain an authentication bypass vulnerability in their web interface, allowing unauthenticated attackers to gain administrative control over device settings. This issue affects network edge devices and could lead to unauthorized configuration changes when reachable.

CVE advisoryCRITICAL

CVE-2017-20234

GarrettCom Magnum Switch Authentication Bypass via Hardcoded String

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

GarrettCom Magnum 6K and 10K managed switches have an authentication bypass vulnerability. Attackers can exploit a hardcoded string to gain unauthorized administrative access and sensitive configuration data without valid credentials, which could be a concern if these devices are network-reachable.

CVE advisoryCRITICAL

CVE-2018-25237

Hirschmann HiSecOS HTTPS Login Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability in Hirschmann HiSecOS devices' HTTPS login interface, when RADIUS authentication is enabled, allows remote attackers to crash the device or execute arbitrary code by sending a password longer than 128 characters. This could impact device availability and integrity.

CVE advisoryCRITICAL

CVE-2026-35561

Amazon Athena ODBC Driver Authentication Session Hijacking Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Amazon Athena ODBC driver has insufficient authentication security controls in its browser-based authentication components, which could allow a threat actor to intercept or hijack authentication sessions. This vulnerability affects versions prior to 2.1.0.0. Organizations using this driver should update to version

CVE advisoryCRITICAL

CVE-2026-35560

Amazon Athena ODBC Driver Credential Interception Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Improper certificate validation in the Amazon Athena ODBC driver may allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers. This vulnerability does not apply to direct connections with Athena.

CVE advisoryCRITICAL

CVE-2026-28766

Gardyn Cloud API Unauthenticated User Data Exposure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability allows unauthenticated access to all registered user account information through a specific cloud API endpoint. This could lead to unauthorized access to sensitive personal data. The reachability and business criticality of this API need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-25197

Authenticated User Profile Pivot Vulnerability in myGardyn Cloud API.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a cloud API that allows authenticated users to access other user profiles by modifying an API call. This could potentially lead to unauthorized access to sensitive data. While the exact impact is uncertain, organizations using this API should investigate their exposure.

CVE advisoryCRITICAL

CVE-2017-20237

Hirschmann Industrial HiVision Authentication Bypass Leads to Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Hirschmann Industrial HiVision's master service, allowing unauthenticated remote attackers to bypass authentication and execute arbitrary commands with administrative privileges. This could lead to unauthorized control over the underlying operating system if the vulnerable interface is reachab

CVE advisoryCRITICAL

CVE-2026-28798

ZimaOS Proxy Endpoint Allows Unauthenticated Localhost Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

ZimaOS, a fork of CasaOS, has a vulnerability in its web interface proxy endpoint that allows unauthenticated access to internal localhost services. This issue, when ZimaOS is reachable from the internet via a Cloudflare Tunnel, can lead to unauthorized access to sensitive local services, posing a significant risk. The

CVE advisoryCRITICAL

CVE-2026-25726

Cloudreve Predictable Secret Key Leads to Full Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cloudreve, a self-hosted file management system, has a critical vulnerability where weak random number generation can allow attackers to predict security secrets, leading to full account takeover and privilege escalation. This means an attacker could potentially forge authentication tokens and gain unauthorized control

CVE advisoryCRITICAL

CVE-2026-32186

Microsoft Bing SSRF Vulnerability Allows Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A server-side request forgery vulnerability in Microsoft Bing allows an attacker to elevate privileges over a network. If reachable, an attacker could trick the service into making requests on their behalf, potentially leading to unauthorized access. This critical vulnerability warrants attention to confirm relevance a

CVE advisoryCRITICAL

CVE-2026-0545

MLflow Unauthenticated Job Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MLflow's job execution endpoints are vulnerable to unauthenticated access when basic authentication is enabled, allowing network clients to submit, read, search, and cancel jobs without credentials. This can result in remote code execution if allowed jobs perform privileged actions, or denial of service and data exposu

CVE advisoryCRITICAL

CVE-2026-28373

Stackfield Desktop App Path Traversal Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A path traversal vulnerability exists in the Stackfield Desktop App, allowing a malicious export to write arbitrary content to any location on a user's filesystem. This poses a business risk of data corruption, unauthorized system modification, or the introduction of malicious files. Organizations should identify affec

CVE advisoryCRITICAL

CVE-2026-35216

Budibase Remote Code Execution via Public Webhook Automation.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can achieve remote code execution on the Budibase low-code platform by triggering an automation with a Bash step via a public webhook. This vulnerability could allow an attacker to run commands as root within the container. This issue has been patched.

CVE advisoryCRITICAL

CVE-2026-31818

Budibase SSRF Vulnerability Allows Unrestricted Requests

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An open-source low-code platform has a server-side request forgery vulnerability in its REST datasource connector. This flaw bypasses built-in protections, potentially allowing attackers to make arbitrary requests to internal or external resources, leading to unauthorized access. Urgency exists to determine if Budibase

CVE advisoryCRITICAL

CVE-2026-31402

Linux kernel could allow external attacker to cause system outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Linux kernel servers to cause complete system outages or gain full administrative control. This matters to the business because it can disrupt critical file-sharing services and expose sensitive files to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-5463

Pymetasploit3 Command Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability in pymetasploit3 allows attackers to execute unintended commands, potentially leading to arbitrary command execution and manipulation of sessions. This impacts organizations using the affected library, posing a risk to data and systems.

CVE advisoryCRITICAL

CVE-2026-33107

Azure Databricks SSRF Vulnerability Allows Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Azure Databricks is susceptible to a server-side request forgery vulnerability that could allow an unauthenticated network attacker to elevate privileges. This means an attacker could potentially gain unauthorized control over the system by tricking the service into making requests on their behalf. It is important to u

CVE advisoryCRITICAL

CVE-2026-33105

Azure Kubernetes Service Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization flaw in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. This could lead to unauthorized access and control of managed resources. The potential impact depends on specific configurations and hosted workloads.

CVE advisoryCRITICAL

CVE-2026-32213

Azure AI Foundry Improper Authorization Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability in Azure AI Foundry could allow an unauthorized attacker to elevate privileges over a network. This could potentially impact the confidentiality, integrity, and availability of affected systems. It is important to confirm if your organization utilizes this service and its network