NVD disclosure day

Published threat advisories for April 6, 2026

CVE advisoryCRITICAL

CVE-2026-35408

Directus SSO OAuth Redirect Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Directus login pages are vulnerable to a cross-origin manipulation that can hijack the Single Sign-On (SSO) OAuth authorization flow. Attackers can exploit this to redirect users to malicious sites, causing them to unknowingly grant access to their authentication provider accounts. This impacts systems where Directus h

CVE advisoryCRITICAL

CVE-2026-35459

pyLoad SSRF Vulnerability Due to Insecure Redirect Handling

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

pyLoad, a Python-based download manager, contains a server-side request forgery vulnerability that an authenticated user can exploit by submitting a URL that redirects to an internal address. This occurs because the software automatically follows HTTP redirects without validating the redirect targets against security f

CVE advisoryCRITICAL

CVE-2026-35197

Dye Template Expression Arbitrary Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the dye color library, a component for shell scripts, allows arbitrary code execution via specific template expressions. This could impact systems processing untrusted input through scripts, though its typical use suggests limited direct external exposure. The issue is fixed in version 1.1.1 and is n

CVE advisoryCRITICAL

CVE-2026-35178

Workbench Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the Salesforce Workbench tool due to unsafe processing of attacker-controlled cookie values in its timezone conversion flow, potentially impacting system data and service behavior. This issue affects versions prior to 65.0.0 and requires confirmation of Workbench

CVE advisoryCRITICAL

CVE-2025-54328

Samsung Exynos SMS Parsing Stack Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow vulnerability in Samsung Exynos processors, impacting mobile and modem firmware, can be triggered by specially crafted SMS messages. This could lead to a compromise of device confidentiality, integrity, and availability. The vulnerability is reachable via the network without authentication

CVE advisoryCRITICAL

CVE-2026-35171

Kedro Unsafe Logging RCE Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Kedro, a data science toolbox, has a critical vulnerability allowing attackers to execute arbitrary system commands during application startup by manipulating an unvalidated logging configuration file via an environment variable. This impacts the integrity and availability of systems using Kedro. Confirming Kedro's pre

CVE advisoryCRITICAL

CVE-2026-35030

LiteLLM JWT Authentication Cache Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in LiteLLM, an AI gateway, could allow an unauthenticated attacker to impersonate legitimate users by exploiting a JWT authentication cache mechanism. This affects deployments where JWT/OIDC authentication is specifically enabled, potentially leading to unauthorized access to user identities and permiss

CVE advisoryCRITICAL

CVE-2026-34977

Aperi'Solve JPEG Upload Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Aperi'Solve, an open-source steganalysis web platform, allows unauthenticated attackers to achieve root-level command execution in the worker container via a single HTTP request. This could result in unauthorized access and modification of user-uploaded images, analysis results, and password