NVD disclosure day

Published threat advisories for April 27, 2026

CVE advisoryCRITICAL

CVE-2026-40971

Spring Boot could allow internal attacker to intercept sensitive message data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in Spring Boot to impersonate a messaging server, allowing them to intercept or tamper with sensitive business data. This could lead to unauthorized data exposure and the disruption of critical application services.

CVE advisoryCRITICAL

CVE-2024-46636

NASA data system vulnerable to data theft or service disruption

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

NASA's Earth Observing system is exposed by a critical vulnerability allowing unauthorized access to data or disruption of services. This SQL injection flaw in MODAPS v8.1 warrants immediate attention due to its potential for broad impact on public-facing systems.

CVE advisoryCRITICAL

CVE-2026-31255

Tenda AC18 router allows attackers to take full control and execute commands due to a security flaw.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit Tenda AC18 routers to run unauthorized commands and take full control of the device. This allows intruders to potentially intercept sensitive traffic or gain unauthorized access to the internal network.

CVE advisoryCRITICAL

CVE-2026-33453

Apache Camel allows attackers to run any command remotely by sending a crafted message

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can send malicious requests to Apache Camel to execute unauthorized commands on the host server. This vulnerability allows the attacker to gain full control over the affected system, risking data exposure and unauthorized access to business operations.

CVE advisoryCRITICAL

CVE-2026-41409

Apache MINA lets attackers take control of services that handle network data.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Apache MINA by sending malicious network data to run unauthorized code on the system. This could allow them to gain full control of affected systems, access sensitive data, and compromise the business environment.

CVE advisoryCRITICAL

CVE-2026-40453

Apache Camel allows attackers to run code or write files by sending specially crafted messages

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Apache Camel could allow an internal attacker to inject malicious commands, enabling them to run unauthorized code and modify system files. This could lead to a full system compromise or unauthorized changes to your server environment.

CVE advisoryCRITICAL

CVE-2026-42363

GeoVision GV-IP Utility could allow an internal attacker to steal credentials and control devices.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker on your network can exploit how GeoVision GV-IP Device Utility handles authentication to steal administrative credentials. This access allows them to take control of devices, potentially causing service disruptions or unauthorized configuration changes.