NVD disclosure day

Published threat advisories for April 23, 2026

CVE advisoryCRITICAL

CVE-2026-41137

Flowise allows attackers to run custom code, potentially stealing sensitive files or customer data.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A security flaw in Flowise allows an external attacker to take full control of the server, potentially exposing sensitive business data. This could lead to the theft of confidential information and the total compromise of your underlying infrastructure.

CVE advisoryCRITICAL

CVE-2026-6920

Google Chrome on Android could allow an external attacker to gain unauthorized device access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in Google Chrome on Android by tricking a user into visiting a malicious website. This allows them to bypass security protections, potentially leading to full device control and unauthorized access to sensitive user information.

CVE advisoryCRITICAL

CVE-2026-31533

Linux kernel could allow external attacker to crash the system

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with local access to the Linux kernel can exploit a flaw in network encryption to corrupt system memory. This could result in a system crash or allow the attacker to gain unauthorized control over core processes, compromising system stability.

CVE advisoryCRITICAL

CVE-2026-40472

Hackage-Server: Stored Cross-Site Scripting Risk in Metadata Rendering.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The hackage-server component allows for the rendering of user-supplied metadata without proper sanitization. This can lead to stored cross-site scripting attacks, potentially impacting users and causing data compromise or service disruption. The business risk involves unauthorized actions or data exposure through malic

CVE advisoryCRITICAL

CVE-2026-40471

Attacker can take control of Hackage server and publish malicious code due to missing security checks.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Malicious websites can hijack your browser to upload fake code or create accounts on the Hackage package server, potentially compromising your software supply chain. This affects an internet-facing platform used for public software distribution.

CVE advisoryCRITICAL

CVE-2026-40470

Attacker can hijack user accounts to change sensitive package information on Haskell's main distribution site.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Hackage's main site allows attackers to hijack user accounts, enabling them to change package details or upload malicious content. This affects authenticated users browsing package pages.

CVE advisoryHIGH

CVE-2026-34003

X.Org Server Vulnerability Allows Information Disclosure and Service Disruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the X.Org X server's request validation may allow a local attacker to access memory out of bounds. This could expose sensitive information or cause a service disruption. In certain configurations, the impact may be greater.

CVE advisoryHIGH

CVE-2026-34001

X.Org Server Use-After-Free Vulnerability in XSYNC Fence Logic.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the X.Org X server's XSYNC fence triggering logic. Attackers with local access can exploit this without user interaction, potentially causing a server crash or memory corruption. This could lead to a denial of service or further system compromise, impacting system availability a

CVE advisoryCRITICAL

CVE-2026-23751

Kofax Capture allows attackers to read or write files and steal credentials.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit an unprotected connection in Tungsten Capture to remotely read or modify files without needing to log in. This exposes the business to unauthorized data theft and allows the attacker to take full control of the server, potentially compromising enterprise document processing.

CVE advisoryCRITICAL

CVE-2026-3844

WordPress Breeze plugin lets attackers upload files to take over your site if Gravatar feature is on.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker could exploit a flaw in the Breeze Cache for WordPress plugin to upload malicious files, provided the "Host Files Locally" feature is enabled. This could lead to a full takeover of the web server, risking sensitive customer data and site availability.

CVE advisoryCRITICAL

CVE-2026-41197

Noir could allow an internal attacker to corrupt program memory and cause crashes.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Noir contains a memory flaw that could allow an internal attacker to corrupt system memory during program compilation. This could enable unauthorized changes to sensitive proof data or the bypass of critical program logic, threatening the integrity of business applications.

CVE advisoryCRITICAL

CVE-2026-41196

Luanti could allow an internal attacker to gain full access to system files.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Luanti allows an internal attacker to execute unauthorized code on the host device by bypassing security restrictions. This vulnerability could lead to full system compromise, resulting in the exposure or modification of sensitive files and data.

CVE advisoryCRITICAL

CVE-2026-41176

Rclone attackers can control your cloud files and data by disabling security features.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can access the Rclone remote control service to disable its security protections without authorization. This allows them to hijack sensitive administrative functions, potentially leading to unauthorized access to your cloud storage data or disruption of critical file synchronization processes.