NVD disclosure day

Published threat advisories for April 3, 2026

CVE advisoryCRITICAL

CVE-2018-25236

Hirschmann HiOS and HiSecOS HTTP(S) Management Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in the HTTP(S) management module of Hirschmann HiOS and HiSecOS products, allowing unauthenticated remote attackers to gain administrative access by crafting special HTTP requests. This could lead to unauthorized control over network services.

CVE advisoryCRITICAL

CVE-2017-20236

ProSoft ICX35-HWC Command Injection via Web Interface

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in ProSoft Technology cellular gateways allowing remote attackers to inject and execute system commands via the web interface. This can lead to root privilege escalation and arbitrary command execution on the device. Confirm if these gateways are in use and exposed to the network.A vulnerability

CVE advisoryCRITICAL

CVE-2017-20235

ProSoft ICX35-HWC Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

ProSoft Technology cellular gateways contain an authentication bypass vulnerability in their web interface, allowing unauthenticated attackers to gain administrative control over device settings. This issue affects network edge devices and could lead to unauthorized configuration changes when reachable.

CVE advisoryCRITICAL

CVE-2017-20234

GarrettCom Magnum Switch Authentication Bypass via Hardcoded String

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

GarrettCom Magnum 6K and 10K managed switches have an authentication bypass vulnerability. Attackers can exploit a hardcoded string to gain unauthorized administrative access and sensitive configuration data without valid credentials, which could be a concern if these devices are network-reachable.

CVE advisoryCRITICAL

CVE-2018-25237

Hirschmann HiSecOS HTTPS Login Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability in Hirschmann HiSecOS devices' HTTPS login interface, when RADIUS authentication is enabled, allows remote attackers to crash the device or execute arbitrary code by sending a password longer than 128 characters. This could impact device availability and integrity.

CVE advisoryCRITICAL

CVE-2017-20237

Hirschmann Industrial HiVision Authentication Bypass Leads to Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Hirschmann Industrial HiVision's master service, allowing unauthenticated remote attackers to bypass authentication and execute arbitrary commands with administrative privileges. This could lead to unauthorized control over the underlying operating system if the vulnerable interface is reachab

CVE advisoryCRITICAL

CVE-2026-0545

MLflow Unauthenticated Job Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MLflow's job execution endpoints are vulnerable to unauthenticated access when basic authentication is enabled, allowing network clients to submit, read, search, and cancel jobs without credentials. This can result in remote code execution if allowed jobs perform privileged actions, or denial of service and data exposu

CVE advisoryCRITICAL

CVE-2026-28373

Stackfield Desktop App Path Traversal Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A path traversal vulnerability exists in the Stackfield Desktop App, allowing a malicious export to write arbitrary content to any location on a user's filesystem. This poses a business risk of data corruption, unauthorized system modification, or the introduction of malicious files. Organizations should identify affec

CVE advisoryCRITICAL

CVE-2026-31402

Linux kernel could allow external attacker to cause system outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Linux kernel servers to cause complete system outages or gain full administrative control. This matters to the business because it can disrupt critical file-sharing services and expose sensitive files to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-5463

Pymetasploit3 Command Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability in pymetasploit3 allows attackers to execute unintended commands, potentially leading to arbitrary command execution and manipulation of sessions. This impacts organizations using the affected library, posing a risk to data and systems.