NVD disclosure day

Published threat advisories for April 3, 2026

CVE advisoryCRITICAL

CVE-2026-28373

Stackfield Desktop App Path Traversal Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A path traversal vulnerability exists in the Stackfield Desktop App, allowing a malicious export to write arbitrary content to any location on a user's filesystem. This poses a business risk of data corruption, unauthorized system modification, or the introduction of malicious files. Organizations should identify affec

CVE advisoryCRITICAL

CVE-2026-31402

Linux kernel could allow external attacker to cause system outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Linux kernel servers to cause complete system outages or gain full administrative control. This matters to the business because it can disrupt critical file-sharing services and expose sensitive files to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-5463

Pymetasploit3 Command Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability in pymetasploit3 allows attackers to execute unintended commands, potentially leading to arbitrary command execution and manipulation of sessions. This impacts organizations using the affected library, posing a risk to data and systems.