NVD disclosure day

Published threat advisories for April 7, 2026

CVE advisoryCRITICAL

CVE-2026-39846

SiYuan Electron Remote Code Execution via Malicious Note Sync.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in SiYuan's desktop client allows remote code execution when a synced, malicious note is opened, due to unescaped table caption content enabling stored XSS. This could allow unauthorized code execution with system access on a user's machine.

CVE advisoryCRITICAL

CVE-2026-34580

Botan Certificate Store Trust Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Botan cryptography library may allow a malicious certificate to be accepted as trusted if its identifying information matches a trusted root. This bypasses intended validation, potentially compromising system security. Confirming relevance and exposure is necessary.

CVE advisoryCRITICAL

CVE-2026-34045

Podman Desktop Unauthenticated HTTP Server Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An unauthenticated HTTP server in Podman Desktop allows network attackers to cause denial-of-service by exhausting system resources, potentially crashing the application or freezing the host. Attackers may also extract sensitive information like internal paths and usernames, which could aid further exploitation. This v

CVE advisoryCRITICAL

CVE-2025-69515

JXL Android Infotainment GPS Spoofing Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An issue affects JXL 9 Inch Car Android Double Din Player systems, enabling attackers to broadcast falsified GPS signals that the infotainment system accepts as legitimate. This could cause the device to report an incorrect or static location, potentially impacting navigation or other location-dependent functions. The

CVE advisoryCRITICAL

CVE-2026-4631

Cockpit Unauthenticated Code Execution via Hostname and Username Injection.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cockpit's remote login feature is vulnerable to unauthenticated code execution. An attacker with network access can send a malicious request to the login endpoint, injecting commands that run on the host before any credentials are checked. This could impact system confidentiality, integrity, and availability. The poten

CVE advisoryCRITICAL

CVE-2026-33816

pgx Go library could allow external attacker to cause application outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can target the pgx Go library by sending specially crafted data to applications communicating with a database. This can corrupt memory and trigger repeated system crashes, leading to severe service outages and disrupted operations for all users.

CVE advisoryCRITICAL

CVE-2026-33815

jackc/pgx database library could allow external attacker to cause service outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can send malicious data to applications using the jackc/pgx database library to trigger system crashes. This can result in persistent service outages, taking down critical business functions by disabling database connectivity.

CVE advisoryCRITICAL

CVE-2026-21413

LibRaw Heap Buffer Overflow in JPEG Loading

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability exists in LibRaw's image loading functionality. An attacker can exploit this by providing a specially crafted malicious file, potentially leading to a crash or further compromise. It is important to identify if your organization uses software that depends on this library and i

CVE advisoryCRITICAL

CVE-2026-20911

LibRaw Heap Buffer Overflow in HuffTable::initval

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability exists in the LibRaw image processing library's HuffTable::initval functionality. Attackers can exploit this by providing a specially crafted malicious file, potentially leading to disruption of operations if affected applications process untrusted image files. The full impact

CVE advisoryCRITICAL

CVE-2026-5735

Memory Corruption in Firefox and Thunderbird Allows Arbitrary Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety vulnerabilities in Firefox and Thunderbird could allow for arbitrary code execution if exploited. This could impact data integrity and confidentiality for users interacting with malicious content or websites through these applications. Uncertainty exists regarding the specific exploitability and potential

CVE advisoryCRITICAL

CVE-2026-5734

Firefox and Thunderbird Memory Safety Vulnerabilities

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety vulnerabilities in Firefox and Thunderbird could permit arbitrary code execution. These flaws are reachable via network access and may allow attackers to compromise affected systems. Organizations should identify and assess instances of these applications to understand potential impact.

CVE advisoryCRITICAL

CVE-2026-5731

Firefox and Thunderbird Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety bugs in certain versions of Firefox and Thunderbird could allow for arbitrary code execution if reachable, impacting user data and application behavior. This vulnerability affects desktop applications and requires user interaction with malicious content to exploit.

CVE advisoryKnown Exploit

CVE-2026-34197

Apache ActiveMQ could allow an internal attacker to take full control of the server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative credentials could take full control of the Apache ActiveMQ server by running malicious commands. This flaw poses a critical business risk, as it could lead to total system compromise and unauthorized access to sensitive message data.

• CISA KEV