NVD disclosure day

Published threat advisories for April 7, 2026

CVE advisoryCRITICAL

CVE-2026-39846

SiYuan Electron Remote Code Execution via Malicious Note Sync.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in SiYuan's desktop client allows remote code execution when a synced, malicious note is opened, due to unescaped table caption content enabling stored XSS. This could allow unauthorized code execution with system access on a user's machine.

CVE advisoryCRITICAL

CVE-2026-34580

Botan Certificate Store Trust Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Botan cryptography library may allow a malicious certificate to be accepted as trusted if its identifying information matches a trusted root. This bypasses intended validation, potentially compromising system security. Confirming relevance and exposure is necessary.

CVE advisoryCRITICAL

CVE-2026-31789

OpenSSL OCTET STRING Heap Overflow on 32-bit Platforms

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap buffer overflow can occur on 32-bit platforms when converting an excessively large OCTET STRING from an X.509 certificate to hexadecimal. This vulnerability may lead to application crashes or potentially allow attackers to execute code, though exploiting it is unlikely due to the extreme certificate size require

CVE advisoryCRITICAL

CVE-2026-39397

Payload Puck API Access Control Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The @delmaredigital/payload-puck plugin for PayloadCMS has a vulnerability that bypasses access controls on its API endpoints. This could allow unauthenticated attackers to perform Create, Read, Update, and Delete operations on data, impacting data security and integrity. Confirming the use of this plugin is necessary

CVE advisoryCRITICAL

CVE-2026-34045

Podman Desktop Unauthenticated HTTP Server Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An unauthenticated HTTP server in Podman Desktop allows network attackers to cause denial-of-service by exhausting system resources, potentially crashing the application or freezing the host. Attackers may also extract sensitive information like internal paths and usernames, which could aid further exploitation. This v

CVE advisoryCRITICAL

CVE-2026-33439

OpenAM Unsafe Java Deserialization RCE Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpenAM, an access management solution, has a critical vulnerability allowing unauthenticated attackers to execute arbitrary commands on the server via unsafe Java deserialization. This bypasses previous mitigations, making systems that use this technology and are reachable potentially susceptible to a complete system c

CVE advisoryCRITICAL

CVE-2026-39382

dbt Actions Shell Command Injection.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a dbt workflow automation script allows for shell command injection through specially crafted GitHub issue comments. If an attacker can influence comment content, arbitrary shell commands could be executed. The risk depends on whether this specific automation workflow is in use.

CVE advisoryCRITICAL

CVE-2026-39322

PolarLearn Bypasses Authentication for Banned Accounts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in PolarLearn's authentication API allows banned accounts to create valid sessions without password verification, potentially enabling unauthorized access to account data and authenticated actions. This issue arises from the API's failure to properly verify supplied passwords before session creation. Wh

CVE advisoryCRITICAL

CVE-2025-69515

JXL Android Infotainment GPS Spoofing Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An issue affects JXL 9 Inch Car Android Double Din Player systems, enabling attackers to broadcast falsified GPS signals that the infotainment system accepts as legitimate. This could cause the device to report an incorrect or static location, potentially impacting navigation or other location-dependent functions. The

CVE advisoryCRITICAL

CVE-2025-71058

Dual DHCP DNS Server DNS Cache Poisoning Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Dual DHCP DNS Server allows remote attackers to poison its DNS cache by sending forged responses, potentially redirecting users to malicious destinations. This could impact network trust and lead to compromise. The exact business impact is uncertain as the reachability of the affected technology is n

CVE advisoryCRITICAL

CVE-2026-39342

ChurchCRM SQL Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

ChurchCRM, an open-source church management system, has a SQL injection vulnerability in its advanced search functionality. An authenticated user with access to reporting features could inject malicious SQL code, potentially leading to unauthorized access or modification of sensitive data. This issue is fixed in versio

CVE advisoryCRITICAL

CVE-2026-4631

Cockpit Unauthenticated Code Execution via Hostname and Username Injection.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cockpit's remote login feature is vulnerable to unauthenticated code execution. An attacker with network access can send a malicious request to the login endpoint, injecting commands that run on the host before any credentials are checked. This could impact system confidentiality, integrity, and availability. The poten

CVE advisoryCRITICAL

CVE-2026-33816

pgx Go library could allow external attacker to cause application outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can target the pgx Go library by sending specially crafted data to applications communicating with a database. This can corrupt memory and trigger repeated system crashes, leading to severe service outages and disrupted operations for all users.

CVE advisoryCRITICAL

CVE-2026-33815

jackc/pgx database library could allow external attacker to cause service outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can send malicious data to applications using the jackc/pgx database library to trigger system crashes. This can result in persistent service outages, taking down critical business functions by disabling database connectivity.

CVE advisoryCRITICAL

CVE-2026-21413

LibRaw Heap Buffer Overflow in JPEG Loading

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability exists in LibRaw's image loading functionality. An attacker can exploit this by providing a specially crafted malicious file, potentially leading to a crash or further compromise. It is important to identify if your organization uses software that depends on this library and i

CVE advisoryCRITICAL

CVE-2026-20911

LibRaw Heap Buffer Overflow in HuffTable::initval

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability exists in the LibRaw image processing library's HuffTable::initval functionality. Attackers can exploit this by providing a specially crafted malicious file, potentially leading to disruption of operations if affected applications process untrusted image files. The full impact

CVE advisoryCRITICAL

CVE-2026-5735

Memory Corruption in Firefox and Thunderbird Allows Arbitrary Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety vulnerabilities in Firefox and Thunderbird could allow for arbitrary code execution if exploited. This could impact data integrity and confidentiality for users interacting with malicious content or websites through these applications. Uncertainty exists regarding the specific exploitability and potential

CVE advisoryCRITICAL

CVE-2026-5734

Firefox and Thunderbird Memory Safety Vulnerabilities

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety vulnerabilities in Firefox and Thunderbird could permit arbitrary code execution. These flaws are reachable via network access and may allow attackers to compromise affected systems. Organizations should identify and assess instances of these applications to understand potential impact.

CVE advisoryCRITICAL

CVE-2026-5731

Firefox and Thunderbird Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety bugs in certain versions of Firefox and Thunderbird could allow for arbitrary code execution if reachable, impacting user data and application behavior. This vulnerability affects desktop applications and requires user interaction with malicious content to exploit.

CVE advisoryKnown Exploit

CVE-2026-34197

Apache ActiveMQ could allow an internal attacker to take full control of the server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative credentials could take full control of the Apache ActiveMQ server by running malicious commands. This flaw poses a critical business risk, as it could lead to total system compromise and unauthorized access to sensitive message data.

• CISA KEV