NVD disclosure day

Published threat advisories for April 15, 2026

CVE advisoryCRITICAL

CVE-2026-6388

ArgoCD Image Updater could allow an internal attacker to make unauthorized application updates.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a weakness in ArgoCD Image Updater to bypass security controls and modify applications belonging to other tenants. This unauthorized access allows them to force the deployment of unauthorized software, which compromises the integrity of critical business applications.

CVE advisoryHIGH

CVE-2026-6363

Google Chrome could allow an external attacker to access memory and potentially crash systems.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in Google Chrome to access sensitive memory and potentially take control of a user's session by tricking them into visiting a malicious website. This matters as it could lead to unauthorized access and control of user data.

CVE advisoryCRITICAL

CVE-2026-6296

Google Chrome could allow external attacker to take control of user computers.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

By tricking employees into visiting a malicious website, an external attacker can exploit a flaw in Google Chrome to seize control of their devices. This allows the attacker to bypass security, gaining full access to business systems and sensitive data located on those computers.

CVE advisoryCRITICAL

CVE-2026-5189

Sonatype Nexus allows attackers to read/write data and run commands due to hard-coded credentials

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A hard-coded security flaw in Sonatype Nexus Repository Manager allows an external attacker to access internal databases and run commands on the server. This could lead to the theft of proprietary software, sabotage of development pipelines, and complete loss of control over the repository server.

CVE advisoryCRITICAL

CVE-2026-6290

Velociraptor allows authenticated users to access data in other organizations.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Velociraptor has a flaw where an internal attacker with access to one organization can run unauthorized queries to access data in other restricted areas. This allows unauthorized access to sensitive information and compromises the security of segregated business environments.

CVE advisoryCRITICAL

CVE-2026-20186

Cisco ISE attacker with admin access can take control and disrupt network access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with existing administrative access to Cisco Identity Services Engine could gain full system control. This allows them to compromise security policies or completely shut down network access for the entire organization.

CVE advisoryCRITICAL

CVE-2026-20180

Cisco ISE allows attackers with admin access to take control of systems and disrupt network access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with limited administrative access to Cisco Identity Services Engine (ISE) can gain full control of the system by executing unauthorized commands. This could allow them to disrupt network connectivity or gain deeper access to critical security infrastructure.

CVE advisoryCRITICAL

CVE-2026-20147

Cisco ISE and PIC can be compromised to take control of systems and disrupt network access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with valid administrative credentials can exploit Cisco ISE to take full control of the system. This access to critical network management allows the attacker to disrupt or disable all enterprise network connectivity.

CVE advisoryCRITICAL

CVE-2026-5387

Attacker can gain admin control over simulation software

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could gain unauthorized administrative access to AVEVA simulation software by bypassing security checks. This allows them to alter sensitive training records and system settings, potentially compromising training data integrity and simulation operations.

CVE advisoryCRITICAL

CVE-2025-14813

Legion of the Bouncy Castle BC-JAVA could allow internal attackers to bypass security measures.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in BC-JAVA's cryptography to weaken encryption, potentially exposing confidential data. This matters to the business as it could lead to unauthorized access to sensitive information.

CVE advisoryCRITICAL

CVE-2026-39842

OpenRemote lets attackers steal sensitive data and control your systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

OpenRemote allows an internal attacker with existing permissions to run unauthorized code, resulting in stolen database credentials and full server control. This flaw risks exposing sensitive data across the entire platform and lets the attacker bypass critical security safeguards.