NVD disclosure day

Published threat advisories for April 29, 2026

CVE advisoryCRITICAL

CVE-2018-25318

Tenda routers can be hijacked to send users to fake websites

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Tenda FH303/A300 routers to manipulate internet traffic routing without needing a password. This allows them to redirect users to malicious websites, creating a significant risk of credential theft and the compromise of sensitive data.

CVE advisoryCRITICAL

CVE-2026-30893

Wazuh could allow internal attacker to gain full administrative control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to Wazuh can overwrite critical files to take full administrative control over monitoring systems. This vulnerability allows them to compromise the security infrastructure and potentially hide malicious activity across the network.

CVE advisoryKnown Exploit

CVE-2026-41940

cPanel and WHM Unauthorized Access Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in cPanel and WHM allows unauthenticated attackers to gain unauthorized access. This presents a significant business risk by potentially exposing sensitive system configurations and data. Organizations using affected versions should prioritize immediate action to identify and secu

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-42523

Jenkins GitHub plugin flaw lets attackers steal admin control.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Jenkins GitHub Plugin contains a flaw that allows an internal attacker with existing access to inject malicious code into the system. This can be used to hijack administrator sessions, potentially leading to unauthorized changes and full control over the CI/CD environment.