NVD disclosure day

Published threat advisories for May 1, 2026

CVE advisoryCRITICAL

CVE-2026-37541

OVMS3 lets attackers take control or shut down vehicle monitoring systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Open Vehicle Monitoring System 3 to send malicious data that crashes the system or allows unauthorized control over vehicle functions. This compromises sensitive telematics data and risks the execution of unauthorized commands on the vehicle.

CVE advisoryCRITICAL

CVE-2026-37539

Attacker could crash systems or take control via crafted frames in cannelloni.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit a flaw in cannelloni by sending malicious data to crash the system or gain full control. This poses a risk to critical communication infrastructure, potentially leading to unauthorized system access or permanent service outages.

CVE advisoryCRITICAL

CVE-2026-37534

Open-SAE-J1939 could allow an internal attacker to gain unauthorized control of system operations.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Open-SAE-J1939 contains a flaw that allows an internal attacker to manipulate how the system processes data. This could enable unauthorized control over connected industrial vehicles or machinery, potentially leading to operational disruption or safety risks.

CVE advisoryCRITICAL

CVE-2026-37531

AGL app framework could allow internal attacker to overwrite critical system files

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The AGL app framework contains a flaw that allows an internal attacker to replace essential system files with malicious ones during application installation. This could grant the attacker administrative control or the ability to run unauthorized code, leading to total system compromise.

CVE advisoryCRITICAL

CVE-2026-42472

MixPHP Framework flaw allows attackers to gain admin control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could take advantage of a flaw in the MixPHP Framework to gain unauthorized control over web servers. This risk could lead to a complete system compromise, allowing an attacker to steal sensitive data or take over the application environment.

CVE advisoryCRITICAL

CVE-2026-43011

Linux kernel X.25 networking could allow internal attacker to cause a system crash

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker could exploit a memory flaw in the Linux kernel to crash systems or gain unauthorized access. This risk threatens business operations, potentially causing service outages and allowing attackers to compromise the security of sensitive systems.

CVE advisoryCRITICAL

CVE-2026-42484

Hashcat could allow an internal attacker to crash the application or take system control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

By processing a malicious file, an internal attacker can cause Hashcat to stop working, resulting in service disruption. This flaw also allows the attacker to execute unauthorized commands, giving them full control over the system.

CVE advisoryCRITICAL

CVE-2026-42779

Apache MINA code flaw lets attackers run any code and take control.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the Apache MINA networking library to gain full control over the server. This access enables unauthorized command execution, which could lead to the theft of sensitive data, installation of malicious software, and a total compromise of business systems.

CVE advisoryCRITICAL

CVE-2026-42996

JS8Call could allow external attacker to compromise the system

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

JS8Call and JS8Call-improved have a flaw where an external attacker can use a crafted radio signal to run unauthorized code on a connected workstation. This could allow the attacker to take full control of the system or disrupt communication services.