NVD disclosure day

Published threat advisories for April 17, 2026

CVE advisoryCRITICAL

CVE-2026-40478

Attacker can take control of web servers using Thymeleaf by sending specially crafted input.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the Thymeleaf Java template engine allows attackers to run unauthorized code on web servers. This means internet-facing applications could be fully compromised if they use unpatched versions and don't properly validate user input.

CVE advisoryCRITICAL

CVE-2026-40258

Gramps Web API allows attackers to write files on the server

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with owner-level access to the Gramps Web API could exploit the media import feature to save files to unauthorized areas, allowing them to overwrite critical configurations or inject malicious code. This enables full application compromise and control over the underlying server.

CVE advisoryCRITICAL

CVE-2026-23500

Dolibarr administrator account can be taken over by attackers via a command injection flaw

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to Dolibarr can modify document settings to run unauthorized commands on the server. This allows them to gain full server control, potentially leading to the theft of sensitive business data and further unauthorized activity on the network.

CVE advisoryCRITICAL

CVE-2026-40342

Firebird database could allow an internal attacker to gain full control of the server.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with specific database permissions can exploit a flaw in the Firebird database to run unauthorized programs. This could allow the attacker to take full control of the host server and access the sensitive business information stored within the system.

CVE advisoryCRITICAL

CVE-2026-35546

Anviz devices let attackers take control by uploading malicious code.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in Anviz CX2 Lite and CX7 devices to upload malicious files and take full administrative control. This allows an unauthorized party to compromise the equipment, potentially leading to persistent, long-term remote access.

CVE advisoryCRITICAL

CVE-2026-6284

Attackers can guess passwords to take control of industrial systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Horner Automation PLCs are vulnerable to weak password security, which allows an internal attacker to gain unauthorized system access. This could allow them to modify critical process settings, potentially resulting in operational disruption or the loss of physical control over equipment.

CVE advisoryCRITICAL

CVE-2026-41153

JetBrains Junie could allow internal attacker to take control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

JetBrains Junie contains a flaw that allows an internal attacker to run unauthorized commands by opening a malicious project file. This could grant them full control of a developer's workstation, enabling the theft of sensitive source code and credentials or the compromise of software products.

CVE advisoryCRITICAL

CVE-2025-15624

Sparx Pro Cloud Server could allow internal attacker to access stored user passwords

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to the Sparx Pro Cloud Server system files can view stored user passwords in plain text. This allows them to hijack accounts, granting unauthorized access to sensitive project models and administrative functions.