NVD disclosure day

Published threat advisories for April 18, 2026

CVE advisoryCRITICAL

CVE-2026-41242

Code injection in protobufjs could allow attackers to run commands on your systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the Protobufjs library to run malicious code on your systems by submitting specially crafted data. This could enable them to compromise backend services, access sensitive configuration details, or gain full control of your applications.

CVE advisoryCRITICAL

CVE-2026-40493

Image library vulnerability allows attackers to crash services or take control.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The SAIL image library contains a flaw that allows an external attacker to crash applications or take control of them by sending a malicious image file. This could lead to service disruptions or unauthorized control over business applications.

CVE advisoryCRITICAL

CVE-2026-40582

ChurchCRM login bypass gives attackers full access to user accounts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An issue in ChurchCRM allows unauthorized access to user accounts by bypassing security features like two-factor authentication. This means someone with just a password could access sensitive information and system functions, so updating to version 7.2.0 is critical.

CVE advisoryCRITICAL

CVE-2026-40484

ChurchCRM can be taken over by attackers due to a dangerous file upload flaw.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can trick an administrator into compromising ChurchCRM, allowing full control over the server and unauthorized access to sensitive member data. This flaw permits the execution of malicious commands that could completely subvert the application’s hosting environment.