NVD disclosure day

Published threat advisories for April 4, 2026

CVE advisoryCRITICAL

CVE-2018-25254

Nico-FTP Structured Exception Handler Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

NICO-FTP has a buffer overflow vulnerability allowing remote attackers to execute arbitrary code via crafted FTP commands. This could impact system integrity and availability if the FTP service is reachable. Confirming NICO-FTP usage and its network exposure is necessary.

CVE advisoryCRITICAL

CVE-2016-20052

Snews CMS 1.7 Unrestricted File Upload Leads to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Snews CMS allows unauthenticated attackers to upload and execute arbitrary files, including PHP executables, potentially leading to remote code execution. This issue impacts the content management system, and its relevance and exposure need to be assessed.

CVE advisoryCRITICAL

CVE-2026-34955

PraisonAI Sandbox Escape Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in PraisonAI's sandbox allows attackers to execute arbitrary commands by bypassing security measures. This could lead to system compromise if the PraisonAI system is exposed to a network. Understanding PraisonAI's deployment and reachability is key to assessing this risk.

CVE advisoryCRITICAL

CVE-2026-34775

Electron Node Integration Escapes Worker Scoping.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Electron framework allows Node.js integration in worker frames under certain configurations, potentially enabling unauthorized access to system functionalities. This affects applications that explicitly enable `nodeIntegrationInWorker` and utilize specific process-sharing scenarios. Understanding