NVD disclosure day

Published threat advisories for April 8, 2026

CVE advisoryCRITICAL

CVE-2026-3199

Sonatype Nexus Repository Authenticated Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Sonatype Nexus Repository allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing security controls. This could impact the integrity and availability of the repository and its managed data. It is important to confirm if this technology is used and accessib

CVE advisoryCRITICAL

CVE-2026-5874

Chrome Sandbox Escape via UI Gestures

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's PrivateAI component may allow a remote attacker to escape the browser sandbox if a user interacts with a malicious HTML page. This could potentially affect sensitive data, and security teams should confirm relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-40035

Unfurl Configuration Parsing Allows Flask Debug Mode Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper input validation vulnerability in Unfurl's configuration parsing can enable Flask debug mode by default. This allows unauthenticated attackers to trigger the Werkzeug debugger, potentially disclosing sensitive information or achieving remote code execution. You should care because this could lead to unautho

CVE advisoryMEDIUM

CVE-2026-39892

Python cryptography Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `cryptography` package is affected by a buffer overflow vulnerability when non-contiguous buffers are passed to specific APIs. If this is reachable, it could potentially lead to memory corruption. Developers should be aware of this issue when using the package.

CVE advisoryCRITICAL

CVE-2026-39890

PraisonAI AgentService YAML Parsing RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in PraisonAI's AgentService, where it parses YAML files without disabling dangerous tags, allowing for remote code execution. An attacker can exploit this by uploading a malicious agent definition file via an API endpoint, potentially leading to a server compromise.

CVE advisoryCRITICAL

CVE-2026-39888

PraisonAI Code Execution Sandbox Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in PraisonAI, a multi-agent system, allows an attacker with limited access to bypass sandbox restrictions and execute arbitrary code. This could lead to a significant compromise of the system by impacting its integrity and confidentiality. It is uncertain if this technology is deployed in your

CVE advisoryCRITICAL

CVE-2026-33466

Logstash Arbitrary File Write via Archive Path Traversal.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Logstash allows an attacker to write arbitrary files to the host filesystem, potentially leading to remote code execution. This is possible if an attacker can serve a specially crafted archive to Logstash via a compromised update endpoint, and the archive's file paths are not properly validated durin

CVE advisoryCRITICAL

CVE-2025-52221

Tenda AC6 Buffer Overflow in formSetCfm Function.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability exists in Tenda AC6 firmware's `formSetCfm` function, allowing unauthenticated network attackers to trigger the flaw via crafted requests. This could lead to potential denial of service or arbitrary code execution, impacting the router's availability and security. Given the cons

CVE advisoryCRITICAL

CVE-2026-31017

ERPNext and Frappe Framework SSRF via PDF Generation Leading to Information Disclosure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Request Forgery vulnerability exists in ERPNext and Frappe Framework's Print Format functionality. This allows attackers to craft HTML that, when rendered into a PDF by the server, can force it to fetch external resources. This could lead to the disclosure of sensitive information if the server is tricked

CVE advisoryCRITICAL

CVE-2023-46945

QD SSRF Vulnerability with Network Attack Vector

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability exists in QD, allowing attackers to trick the application into making unintended network requests. This could potentially expose sensitive system information or allow interaction with other services. The primary concern is confirming the relevance and exposure of affected QD

CVE advisoryCRITICAL

CVE-2026-31040

Stata-mcp Command Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in stata-mcp allows for command execution through insufficient validation of user-supplied do-file content. If reachable, this could lead to unauthorized actions on affected systems. Understanding how this tool is integrated into your environment is crucial.

CVE advisoryCRITICAL

CVE-2026-39394

CI4MS Installer Arbitrary Configuration Directive Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in CI4MS allows an unauthenticated attacker to inject arbitrary configuration directives into the `.env` file by exploiting the installation controller. This is possible because installation routes do not validate input containing newline characters and may lack necessary protections, potential

CVE advisoryCRITICAL

CVE-2026-5300

CoolerControl coolercontrold Unauthenticated Data Exposure and Modification via HTTP

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Unauthenticated access to CoolerControl's coolercontrold software allows attackers to view and modify sensitive data via HTTP requests, posing a critical risk. While typically used for local management, confirming its network exposure within your environment is essential to understand its relevance and potential impact

CVE advisoryCRITICAL

CVE-2026-39640

Theme Editor Plugin CSRF to Code Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical Cross-Site Request Forgery vulnerability in a WordPress theme editor plugin can allow for code injection if users interact with malicious content. This could impact website integrity and administrative control by enabling attackers to inject and execute arbitrary code. The primary concern is confirming if th

CVE advisoryCRITICAL

CVE-2026-39620

Appointment Theme CSRF Upload Web Shell Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Cross-Site Request Forgery vulnerability in the Appointment appointment system allows an attacker to upload a web shell to the web server, potentially enabling unauthorized server control. This issue is relevant because web themes are typically exposed to the public internet.

CVE advisoryCRITICAL

CVE-2026-39619

Busiprof Theme CSRF Allows Web Shell Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Cross-Site Request Forgery vulnerability exists in the Busiprof theme, allowing an attacker to trick a user into uploading a web shell to a web server. This could lead to server compromise and data exposure, impacting web application integrity. The vulnerability requires user interaction and triggers file up

CVE advisoryCRITICAL

CVE-2026-39617

Bluestreet CSRF Vulnerability Allows Arbitrary Plugin Installation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Cross-Site Request Forgery vulnerability exists in the Bluestreet WordPress theme. If reachable, an attacker could trick a user into unknowingly performing unauthorized actions, potentially leading to arbitrary plugin installation. Confirming relevance to our web presence is advised.

CVE advisoryCRITICAL

CVE-2026-25776

Movable Type Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical code injection vulnerability exists in Movable Type, a content management system. This flaw could permit an attacker to execute arbitrary Perl scripts, potentially impacting system integrity and availability. It is important to determine if Movable Type is used within the environment.

CVE advisoryCRITICAL

CVE-2026-3535

DSGVO Google Web Fonts GDPR Plugin Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The DSGVO Google Web Fonts GDPR plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on public-facing websites. This issue arises from inadequate file type validation within a plugin function that is accessible wi

CVE advisoryCRITICAL

CVE-2026-4003

WordPress Users Manager PN Plugin Privilege Escalation via Arbitrary User Meta Update.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin contains a privilege escalation vulnerability, allowing unauthenticated attackers to update user metadata. This could lead to unauthorized access and modification of sensitive user data on reachable WordPress sites.

CVE advisoryCRITICAL

CVE-2026-3296

Everest Forms PHP Object Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Everest Forms WordPress plugin has a PHP Object Injection vulnerability. Unauthenticated attackers can inject serialized PHP objects through public form fields, leading to potential site compromise when administrators view entries due to insecure deserialization.

CVE advisoryCRITICAL

CVE-2026-27143

Go Compiler Arithmetic Issue Allows Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Go compiler where unchecked arithmetic operations in loops can lead to invalid memory indexing and potential memory corruption at runtime. This affects the compilation process and could impact the integrity of programs built with affected versions. Confirming the use of Go in your