NVD disclosure day

Published threat advisories for April 14, 2026

CVE advisoryCRITICAL

CVE-2026-35589

Nanobot could allow external attacker to hijack WhatsApp messages and accounts.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can target the nanobot assistant when a user visits a malicious website to take control of their WhatsApp account. This allows the attacker to read private messages, steal sensitive login credentials, and send messages as the user, exposing confidential business communications.

CVE advisoryKnown Exploit

CVE-2026-33825

Microsoft Defender could allow internal attacker to gain administrative access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with standard user access can exploit a flaw in Microsoft Defender to gain full administrative access. This allows them to disable security software and modify critical policies, creating a risk of unauthorized control over the entire system.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-33824

Attackers can run code over the network on Windows systems to steal data or disrupt services

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Windows' IKE Extension allows attackers to run code remotely over the network, potentially impacting data security and service availability. This issue warrants immediate attention due to its broad reach and ease of exploitation.

CVE advisoryKnown Exploit

CVE-2026-32202

Windows could allow an external attacker to impersonate trusted network sources

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the Windows Shell within Microsoft Windows could allow an external attacker to impersonate trusted services and trick users into interacting with malicious resources. This could lead to the theft of sensitive credentials or unauthorized access to corporate systems.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-27303

Adobe Connect could allow an external attacker to run unauthorized code on user devices.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit Adobe Connect by tricking employees into clicking malicious links, enabling the execution of unauthorized code on their devices. This could allow attackers to steal sensitive meeting data and confidential files, resulting in the compromise of organizational information.

CVE advisoryCRITICAL

CVE-2026-26149

Microsoft Power Apps lets attackers steal control of apps and customer data

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with access to Microsoft Power Apps can manipulate displayed information to impersonate trusted sources. This allows them to deceive staff into providing sensitive credentials or accessing unauthorized data, damaging the integrity of internal business operations.

CVE advisoryCRITICAL

CVE-2026-39813

Fortinet FortiSandbox flaw could let an attacker take full control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a weakness in Fortinet FortiSandbox to bypass file restrictions and gain unauthorized administrative control. This could allow them to compromise the device, potentially undermining your organization's network defenses.

CVE advisoryCRITICAL

CVE-2026-39808

FortiSandbox allows attackers to run unauthorized commands due to a software flaw

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the Fortinet FortiSandbox to run unauthorized commands. This allows them to gain full administrative control of the security appliance, potentially enabling persistent access and deeper intrusion into the corporate network.