NVD disclosure day

Published threat advisories for April 9, 2026

CVE advisoryCRITICAL

CVE-2026-33784

Juniper JSI vLWC Default Password Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Use of Default Password vulnerability in Juniper Networks Support Insights Virtual Lightweight Collector (vLWC) allows unauthenticated network attackers to gain full control of the device. This occurs because the initial password for a high-privilege account is not always changed during setup. This could expose sensi

CVE advisoryCRITICAL

CVE-2026-33771

Juniper CTP OS Weak Password Requirements Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Juniper CTP OS password management could allow an unauthenticated attacker to exploit weak passwords and gain full control of devices. This is because password complexity requirements are not persistently saved, leading to weak passwords that attackers may be able to guess. The primary concern is und

CVE advisoryCRITICAL

CVE-2026-40089

Sonicverse Radio Streaming: Server-Side Request Forgery.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Sonicverse Radio Audio Streaming Stack installations using the provided script are affected by a vulnerability in the dashboard's API client. An authenticated operator can exploit this flaw to make unauthorized HTTP requests from the dashboard backend, potentially exposing internal or external systems and increasing bu

CVE advisoryCRITICAL

CVE-2026-39912

V2Board Xboard Authentication Token Exposure Via LoginWithMailLink

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability exists in V2Board and Xboard, allowing attackers to obtain authentication tokens by sending a request to the `loginWithMailLink` endpoint. If this feature is enabled, the exposed token can be exchanged for a valid bearer token, granting complete account access, including administrative

CVE advisoryCRITICAL

CVE-2026-34971

Wasmtime Cranelift Arbitrary Host Memory Read Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Wasmtime's Cranelift compilation backend allows a malicious WebAssembly module to read and write arbitrary host memory when specific conditions are met. This sandbox escape occurs due to a miscompile of heap accesses on certain hardware configurations when Spectre mitigations or signals-based traps a

CVE advisoryKnown Exploit

CVE-2026-39987

Marimo could allow an external attacker to take full control of the server.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit Marimo to bypass security controls and gain full control of the server. This allows them to run unauthorized commands, access sensitive data, and potentially compromise the broader company network.

• CISA KEV

CVE advisoryHIGH

CVE-2026-4878

Libcap Vulnerability Allows Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A local unprivileged user can exploit a race condition in libcap, potentially leading to privilege escalation. Attackers with write access to a parent directory can manipulate file capabilities on unintended executables. This impacts affected systems by allowing unauthorized privilege elevation.