NVD disclosure day

Published threat advisories for April 24, 2026

CVE advisoryCRITICAL

CVE-2026-41328

Dgraph database allows attackers full access to all customer data without authentication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the Dgraph database to bypass security and gain full access to all stored information. This allows unauthorized parties to steal or expose sensitive organizational data, resulting in a potential total breach of critical business records.

CVE advisoryCRITICAL

CVE-2026-42043

Attacker can bypass security controls to access sensitive files or disrupt services using Axios

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Axios to bypass security settings, allowing them to reach private internal services that should remain isolated. This access could result in unauthorized data exposure or administrative control over critical internal systems.

CVE advisoryCRITICAL

CVE-2026-31668

Linux kernel could allow internal attacker to bypass network routing security

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in the Linux kernel to bypass established network security controls. This enables them to misdirect traffic, potentially leading to the interception of sensitive data or unauthorized access to restricted network segments.

CVE advisoryCRITICAL

CVE-2026-31657

Linux batman-adv module could allow internal attacker to cause system crashes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to a local network using the Linux batman-adv module could trigger a system crash. This is a business risk because it allows an unauthorized user to disrupt network connectivity and force key infrastructure nodes offline.

CVE advisoryCRITICAL

CVE-2026-31649

Linux network driver could allow external attacker to disclose sensitive system memory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Linux kernel network driver allows an internal attacker with local access to compromise system memory. This could enable unauthorized access to sensitive information or lead to system crashes, risking both data security and business operations.

CVE advisoryCRITICAL

CVE-2026-31637

Linux kernel flaw lets attackers control systems remotely

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit an error in the Linux kernel’s network authentication process by sending malicious data packets. This could allow them to crash systems or bypass security, posing a significant risk to service availability and unauthorized system access.

CVE advisoryCRITICAL

CVE-2026-31636

Linux kernel allows attackers to read sensitive memory via network access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a vulnerability in the Linux kernel to access sensitive system memory. This can lead to the unauthorized exposure of confidential data and may help an attacker bypass security protections to compromise the affected system.

CVE advisoryCRITICAL

CVE-2026-31633

Linux kernel vulnerability allows attackers to bypass security checks and gain control.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can send malicious network traffic to the Linux kernel, causing system crashes or service outages. This vulnerability could allow unauthorized code to run or grant attackers higher system access, threatening the stability and security of business operations.

CVE advisoryCRITICAL

CVE-2026-31608

Linux kernel bug could allow attackers to disrupt services or access sensitive files.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can send malicious network requests to the Linux kernel SMB server to corrupt system memory and trigger a crash. This could result in service outages, disrupting critical file sharing and resource management capabilities essential for business operations.

CVE advisoryCRITICAL

CVE-2026-31607

Linux USB/IP could allow an external attacker to crash the system.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel USB/IP component has a flaw that allows an external attacker to crash the system or gain unauthorized control. By directing a user to a malicious server, the attacker could trigger system failures and compromise sensitive business operations.

CVE advisoryCRITICAL

CVE-2026-31589

Linux kernel could allow internal attacker to cause system crashes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing system access could exploit a flaw in the Linux kernel to crash the system or gain total control. This allows them to compromise the operating system, potentially leading to unauthorized data access and significant service downtime.

CVE advisoryCRITICAL

CVE-2026-31536

Linux kernel vulnerability could allow attackers to take control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Linux kernel contains a flaw in its file-sharing software that could allow an internal attacker to disrupt business operations. By targeting network connections, they could trigger memory errors that lead to system crashes and service outages.

CVE advisoryCRITICAL

CVE-2026-25660

CodeChecker allows attackers to change user permissions

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the CodeChecker web interface to bypass security checks and grant themselves or others elevated access rights. This could lead to unauthorized control over sensitive code analysis data and project defect information.

CVE advisoryCRITICAL

CVE-2026-1951

Delta AS320T controls can be fully compromised by attackers

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Delta Electronics AS320T has a security flaw that allows an internal attacker to disrupt system operations or take control of the device by sending invalid requests. This could lead to a loss of control over critical industrial processes and halt production workflows.

CVE advisoryCRITICAL

CVE-2026-1950

Delta AS320T can be taken over by attackers due to a file name flaw.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a file name error in the Delta Electronics AS320T to potentially gain administrative control or crash the system. This risk could lead to unauthorized modification of industrial control operations or critical service disruptions.

CVE advisoryCRITICAL

CVE-2026-41323

Kyverno could allow internal attacker to gain full cluster control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in Kyverno to trick the system into sending sensitive authentication tokens to an unauthorized server. This allows them to steal administrative access and take full control of the entire computing cluster.

CVE advisoryCRITICAL

CVE-2026-27843

Attackers can lock down SenseLive X3050 devices, disrupting operations and requiring expert help to restore.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An attacker can lock out SenseLive X3050 devices through their web interface, causing a complete disruption that needs expert intervention to fix. This affects critical gateway functions and connected systems.