NVD disclosure day

Published threat advisories for April 28, 2026

CVE advisoryCRITICAL

CVE-2026-7333

Google Chrome could allow an external attacker to take control of the computer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can trick users into visiting a malicious website to exploit a flaw in Google Chrome, allowing them to bypass security protections and take control of the affected computer. This issue could lead to unauthorized system access and the potential compromise of sensitive corporate data.

CVE advisoryCRITICAL

CVE-2026-41446

Snap One WattBox devices allow attackers full control with device serial number.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Snap One WattBox 800 and 820 series devices have a flaw that allows an internal attacker with physical label access to gain full administrative control. They could use this access to manipulate power distribution or disable connected equipment, leading to a loss of control over critical infrastructure.

CVE advisoryCRITICAL

CVE-2026-3893

Carlson GNSS Receiver easily compromised without password impacting operations

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can reach the Carlson VASCO-B GNSS Receiver over the network because it lacks security checks. This allows them to change device settings, which could lead to loss of control over the equipment or the disruption of industrial operations.

CVE advisoryCRITICAL

CVE-2026-24178

Attackers can bypass security controls on NVIDIA NVFlare to steal data or take control of systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the NVIDIA NVFlare Dashboard to bypass security controls and gain full administrative access. This allows unauthorized individuals to access restricted data, execute commands, or disrupt operations within your managed environment.

CVE advisoryCRITICAL

CVE-2026-7321

Mozilla Firefox and Thunderbird could allow an external attacker to gain control of user systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could take control of systems running Mozilla Firefox and Thunderbird by luring users to a malicious website to bypass security protections. This could result in the theft of sensitive files or credentials stored on the device.

CVE advisoryCRITICAL

CVE-2026-5779

MphRx Minerva lets attackers take over accounts by changing user info

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can manipulate account settings in MphRx Minerva to modify another user's email address, allowing them to reset passwords and take over that account. This flaw puts sensitive user data at risk and could lead to unauthorized access to privileged accounts.

CVE advisoryCRITICAL

CVE-2026-32644

Milesight cameras could be taken over due to default security settings.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain Milesight AIOT cameras have a security flaw allowing attackers to easily impersonate them, potentially accessing sensitive video feeds and data. This is a serious concern as these cameras are often connected to networks for remote monitoring.

CVE advisoryCRITICAL

CVE-2026-40974

Spring Boot could allow internal attacker to intercept database data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Spring Boot contains a flaw that could allow an internal attacker to intercept or modify data sent between the application and its database. This could expose sensitive information or lead to corrupted records, posing a significant risk to data confidentiality.