NVD disclosure day

Published threat advisories for April 16, 2026

CVE advisoryCRITICAL

CVE-2026-5426

Digital Knowledge KnowledgeDeliver lets attackers take control of systems over the internet

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Digital Knowledge KnowledgeDeliver has a critical flaw allowing unauthenticated attackers to gain full system control over the internet. This issue, due to hard-coded security secrets, means affected systems are at immediate risk.

CVE advisoryCRITICAL

CVE-2026-37345

Attacker can steal customer data or disrupt parking system operations

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit the SourceCodester Vehicle Parking Area Management System to access the backend database. This allows them to steal administrative credentials or sensitive parking records, potentially leading to a complete compromise of the system’s data.

CVE advisoryCRITICAL

CVE-2024-2374

WSO2 products can expose customer data and control due to insecure XML handling.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WSO2 products can be tricked into revealing sensitive files or system information because their XML processors allow attackers to provide specially crafted data that causes the system to fetch unwanted content. This could lead to significant data exposure or service disruption.

CVE advisoryCRITICAL

CVE-2026-22619

Eaton Intelligent Power Protector could allow internal attacker to run unauthorized code.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker could exploit Eaton Intelligent Power Protector to run unauthorized code on the host system. This allows them to gain administrative control over critical power management infrastructure, potentially compromising the underlying server.

CVE advisoryCRITICAL

CVE-2026-6349

HGiga iSherlock could allow internal attacker to gain full server control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a vulnerability in HGiga iSherlock to run unauthorized commands on the server. This allows them to gain full control of the system, potentially resulting in the theft of sensitive information and further unauthorized access to your private company network.

CVE advisoryCRITICAL

CVE-2026-6348

Simopro WinMatrix agent allows internal attackers to run any code with full admin rights.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit the WinMatrix agent to gain full admin rights, risking widespread network compromise. This allows them to execute commands and control the entire infrastructure where the agent is deployed.

CVE advisoryCRITICAL

CVE-2026-40504

Creolabs Gravity allows attackers to take control of your systems by crafting scripts.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a security flaw in Creolabs Gravity by submitting malicious scripts to the application, allowing them to gain full control over the host system. This creates a significant risk of unauthorized access to business data and complete compromise of the underlying infrastructure.