NVD disclosure day

Published threat advisories for April 20, 2026

CVE advisoryCRITICAL

CVE-2026-32613

Spinnaker allows attackers to control systems or steal data by exploiting an Echo service flaw.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with access to Spinnaker’s deployment pipeline can run unauthorized commands or access restricted system files. This could allow them to take complete control of your continuous delivery platform and gain unauthorized access to your wider production cloud environments.

CVE advisoryCRITICAL

CVE-2026-32604

Spinnaker allows attackers to steal credentials and control your systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Spinnaker to run unauthorized commands on the server. This could allow them to steal sensitive cloud credentials, modify production infrastructure, and compromise the integrity of the software delivery process.

CVE advisoryCRITICAL

CVE-2026-29646

OpenXiangShan NEMU could allow an internal attacker to break system isolation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to a virtual machine on OpenXiangShan NEMU could bypass security controls to interfere with the host server. This flaw risks the integrity of the host environment, potentially allowing the attacker to disrupt operations or gain unauthorized access.

CVE advisoryCRITICAL

CVE-2026-29649

NEMU could allow internal attacker to cause service disruptions

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with privileged guest access can exploit a flaw in the NEMU virtualization software to cause system crashes or disrupt virtualized services. This unauthorized activity threatens the stability and reliability of business-critical workloads.

CVE advisoryCRITICAL

CVE-2026-30269

Doorman users can gain admin control by changing their roles

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with a standard user account can manipulate their Doorman profile to grant themselves administrative rights. This flaw allows a user to bypass permission settings and could lead to unauthorized access to sensitive data or full control over the platform.

CVE advisoryCRITICAL

CVE-2026-39918

Vvveb installer can let attackers run any code to steal data or control systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the Vvveb installation process to run malicious commands on the server without needing credentials. This allows them to take full control of the web server, which could compromise all hosted data and business applications.

CVE advisoryCRITICAL

CVE-2026-5760

Attackers can take over SGLang systems by loading a malicious model file.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit SGLang by sending malicious instructions to the reranking feature. This flaw allows them to execute unauthorized code on the server, potentially stealing sensitive configuration data or gaining full control over the host system.

CVE advisoryCRITICAL

CVE-2026-33557

Apache Kafka accepts fake security tokens allowing unauthorized access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Apache Kafka has a flaw that allows an external attacker to fake their identity and impersonate any user, including administrators. This could grant unauthorized access to sensitive business data and enable the manipulation of critical message streams.

CVE advisoryCRITICAL

CVE-2026-6644

Asustor Data Master can be fully compromised by attackers

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to ADM could modify VPN settings to take full control of the system. This level of access could allow them to plant backdoors or steal sensitive files, potentially resulting in a complete compromise of the device.

CVE advisoryCRITICAL

CVE-2026-32956

Attackers can take over Silex SD-330AC and AMC Manager devices.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit Silex SD-330AC and AMC Manager to run unauthorized code on the device. This flaw could grant them full control over network hardware, potentially allowing them to compromise your network or establish persistent access.