NVD disclosure day

Published threat advisories for April 21, 2026

CVE advisoryCRITICAL

CVE-2026-40911

WWBN AVideo flaw lets attackers steal accounts and sessions over the internet

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical flaw in WWBN AVideo lets anyone steal accounts and sessions by broadcasting malicious code to all users. This impacts internet-facing video platforms, making it easy for attackers to take over user accounts and run commands.

CVE advisoryCRITICAL

CVE-2026-34287

Attacker can change or steal Oracle Identity Manager data over the network

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the Oracle Identity Manager Connector to bypass security and access or manipulate critical identity records. This allows them to create, delete, or modify sensitive business data, potentially compromising the integrity of identity management systems.

CVE advisoryCRITICAL

CVE-2026-34286

Attacker can steal or change customer data in Oracle Identity Manager Connector

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the Oracle Identity Manager Connector to access, modify, or delete sensitive identity records without needing to log in. This could lead to unauthorized administrative control over enterprise systems, placing critical business data and security at risk.

CVE advisoryCRITICAL

CVE-2026-34285

Oracle Identity Manager Connector allows attackers to alter critical data

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the Oracle Identity Manager Connector to access, modify, or delete sensitive identity data without logging in. This could allow unauthorized access to connected organizational resources and lead to the compromise of critical enterprise credentials.

CVE advisoryCRITICAL

CVE-2026-34279

Attacker can take over Oracle Enterprise Manager affecting customer data and services

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with existing administrative credentials could take over the Oracle Enterprise Manager Base Platform. This would allow them to seize control of managed infrastructure and compromise the wider IT environment.

CVE advisoryCRITICAL

CVE-2026-33519

Esri Portal for ArcGIS allows attackers to take control due to stolen developer credentials

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with valid developer credentials can exploit a flaw in Esri Portal for ArcGIS to bypass permission checks, enabling unauthorized access to private geospatial datasets and sensitive map configurations. This poses a risk of administrative compromise and the exposure of confidential organizational da…

CVE advisoryHIGH

CVE-2026-33518

ArcGIS Portal could allow attackers with admin access to gain extra privileges

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with existing high-level access to Esri Portal for ArcGIS could exploit a credential creation flaw to grant themselves unauthorized administrative privileges. This allows them to access sensitive information and gain control over the platform, jeopardizing business operations.

CVE advisoryCRITICAL

CVE-2026-40903

goshs server leaks sensitive GitHub tokens through artifacts

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit the goshs file server to retrieve sensitive GitHub access tokens embedded in build artifacts. This grants unauthorized access to our code repositories and deployment pipelines, potentially leading to data theft or software supply chain tampering.

CVE advisoryCRITICAL

CVE-2026-40887

Vendure Shop API flaw lets attackers steal customer data or disrupt services.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated flaw in the Vendure Shop API lets attackers run malicious commands against your database, potentially exposing customer data or disrupting services. This is critical as it affects public-facing commerce operations and all major databases.

CVE advisoryCRITICAL

CVE-2026-5652

Crafty Controller allows attackers to change user data due to incorrect permissions.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Crafty Controller contains a flaw that allows an internal attacker with valid credentials to modify settings for other users. This unauthorized access can lead to a complete takeover of administrative accounts, giving the attacker control over the server management interface.

CVE advisoryCRITICAL

CVE-2026-40050

LogScale can expose sensitive files if not properly secured.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can take advantage of a security issue in CrowdStrike LogScale to remotely access sensitive server files, such as configuration data and stored credentials. This unauthorized access could allow them to gain administrative control over the server or view integrated business data.

CVE advisoryCRITICAL

CVE-2026-21571

Attackers can control your systems by sending commands through Bamboo Data Center.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with valid credentials can take full control of Bamboo Data Center to manipulate build plans and steal sensitive data. This flaw puts the integrity of critical development pipelines at risk and could expose interconnected business systems.

CVE advisoryCRITICAL

CVE-2025-41029

Zeon Academy Pro lets attackers steal or change your data

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Zeon Academy Pro to view, modify, or delete sensitive information in the company database. This access allows the attacker to steal user records or take over accounts, resulting in a loss of critical business data and operational control.

CVE advisoryCRITICAL

CVE-2017-20230

Storable allows attackers to crash systems or take control.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can submit malicious inputs to applications using the Perl Storable module to trigger memory errors. This allows them to run unauthorized code or crash the system, potentially resulting in full control over the host application or service interruptions.

CVE advisoryCRITICAL

CVE-2026-6771

Firefox and Thunderbird could allow an external attacker to bypass security protections

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit Firefox and Thunderbird by luring users to malicious websites or email content. By bypassing security protections, they could execute unauthorized code and steal sensitive user data or credentials, risking unauthorized access to business systems.

CVE advisoryCRITICAL

CVE-2026-6768

Firefox and Thunderbird could allow an external attacker to bypass security measures.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can trick users of Firefox and Thunderbird into visiting malicious websites to bypass session protections. This could allow them to compromise active web sessions, potentially leading to unauthorized account access and exposure of sensitive data.

CVE advisoryCRITICAL

CVE-2026-6760

Firefox and Thunderbird could allow an external attacker to access sensitive cookie data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Firefox and Thunderbird by luring users to malicious websites to bypass security controls and steal sensitive cookie data. This could allow the attacker to hijack active sessions and gain unauthorized access to user accounts.

CVE advisoryCRITICAL

CVE-2026-6748

Firefox and Thunderbird could allow an external attacker to take control of your device.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Firefox and Thunderbird contain a flaw that allows an external attacker to steal sensitive personal information or hijack active user sessions. This risk arises when an employee views malicious web content, potentially exposing stored credentials and private data to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-41329

OpenClaw could allow an internal attacker to gain unauthorized administrative access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker could exploit a flaw in OpenClaw to bypass its security boundaries and escalate their access privileges. This could result in unauthorized administrative control over the host system and compromise protected business resources.