NVD disclosure day

Published threat advisories for May 4, 2026

CVE advisoryCRITICAL

CVE-2026-42222

Attackers can take over Nginx UI systems during installation to access sensitive data and gain admin control.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Unauthenticated attackers can completely take over the Nginx UI system during its initial setup, potentially accessing sensitive data and gaining administrative control. This is a critical issue with no immediate patch available.

CVE advisoryCRITICAL

CVE-2026-41926

WDR201A WiFi Extender can be taken over by attackers

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can send malicious commands to the WDR201A WiFi Extender's firewall settings to gain administrative access. This allows the attacker to silently monitor or manipulate sensitive network traffic and establish a persistent foothold within the organization’s network.

CVE advisoryCRITICAL

CVE-2026-41924

WDR201A WiFi extender allows attackers to run any command remotely, potentially taking control of your network.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can remotely take control of the WDR201A WiFi Extender by tricking it into running unauthorized commands. This could allow them to intercept sensitive network traffic or use the device as a launchpad to access the rest of your internal company network.

CVE advisoryCRITICAL

CVE-2026-41923

WDR201A WiFi Extender allows attackers to control your network from anywhere.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The WDR201A WiFi Extender contains a security flaw that allows an external attacker to remotely take complete control of the device without a password. This exposes the business to credential theft, interception of network traffic, and unauthorized access to internal systems.

CVE advisoryCRITICAL

CVE-2026-41922

WDR201A WiFi Extender allows attackers to take control of devices over the network

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The WDR201A WiFi Extender contains a flaw that allows an external attacker to take full control of the device without requiring login credentials. This exposes your network traffic to potential interception and enables unauthorized access to your private infrastructure.

CVE advisoryCRITICAL

CVE-2026-42232

Attacker can take control of n8n with existing access, risking customer data and service disruption.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with workflow access can compromise the n8n platform by submitting malicious data. This allows them to run unauthorized commands to gain full control of the server, potentially exposing sensitive business data and privileged API keys.

CVE advisoryCRITICAL

CVE-2026-42796

Arelle allows attackers to run their code, potentially leading to data theft or service disruption.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Arelle to remotely run unauthorized code without needing credentials. This allows them to take full control of the server, potentially leading to the theft of sensitive financial reporting data.

CVE advisoryCRITICAL

CVE-2026-42812

Apache Polaris could allow an internal attacker to expose or corrupt sensitive data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing access to Apache Polaris can manipulate table settings to direct data storage to unauthorized locations. This flaw could allow them to expose sensitive company information or corrupt critical files.

CVE advisoryCRITICAL

CVE-2026-42811

Apache Polaris allows attackers to access any file in a bucket, not just specific tables.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Apache Polaris contains a flaw that allows an internal attacker with table management permissions to bypass access restrictions for cloud storage. By providing crafted names, they can gain unauthorized access to read, change, or delete sensitive data across an entire storage bucket, putting business information at ris…

CVE advisoryCRITICAL

CVE-2026-42810

Apache Polaris could allow an internal attacker to access or modify sensitive data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in Apache Polaris to bypass cloud storage security and access, modify, or delete sensitive business data. This vulnerability poses a significant risk to data privacy and could allow unauthorized destruction of proprietary information.

CVE advisoryCRITICAL

CVE-2026-42809

Apache Polaris weakness lets attackers control data access credentials

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can manipulate Apache Polaris table creation requests to obtain unauthorized credentials for restricted storage locations. This flaw allows unauthorized parties to steal or modify sensitive cloud data, impacting business information integrity.

CVE advisoryCRITICAL

CVE-2026-42376

D-Link DIR-456U could allow an internal attacker to gain full device control.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a hardcoded password in the D-Link DIR-456U Hardware Revision A1 to gain full administrative control of the device. This access allows an attacker to intercept network traffic or move further into the business network.

CVE advisoryCRITICAL

CVE-2026-42090

Notesnook could allow an internal attacker to take full control of the user's computer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could take full control of a computer running Notesnook if a user exports a malicious note to PDF. This action enables the attacker to run hidden commands, risking total system compromise and unauthorized access to the victim's sensitive personal information.

CVE advisoryCRITICAL

CVE-2026-42027

Apache OpenNLP allows attackers to run malicious code via crafted model files

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a vulnerability in Apache OpenNLP by providing a malicious model file to execute unauthorized commands on your systems. This could result in the theft of sensitive business credentials or unauthorized access to internal files.

CVE advisoryCRITICAL

CVE-2026-40682

Apache OpenNLP allows attackers to steal files or trick systems into visiting attacker sites

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

By submitting a manipulated dictionary file to Apache OpenNLP, an external attacker can trick the system into revealing sensitive files or internal network data. This creates a risk of unauthorized access to business credentials and configuration information.

CVE advisoryCRITICAL

CVE-2026-26956

vm2 sandbox escape allows attackers to run commands on your systems

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in the vm2 software allows an external attacker to bypass security controls and run unauthorized commands on the underlying server. This risk could lead to a full system compromise, granting the attacker control over server operations and access to sensitive data.

CVE advisoryCRITICAL

CVE-2026-26332

vm2 sandbox escape allows attackers to run any code, stealing customer data or disrupting services.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the vm2 software to bypass security controls, allowing them to take control of the server. This could lead to a breach of sensitive data or total system compromise, giving unauthorized users access to the underlying infrastructure.

CVE advisoryCRITICAL

CVE-2026-25293

Qualcomm PLC firmware allows attackers to take control or disrupt service

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a flaw in Qualcomm PLC firmware to gain control over the device and run unauthorized commands. This poses a business risk by allowing the attacker to disrupt critical industrial operations or potentially manipulate connected physical equipment.

CVE advisoryCRITICAL

CVE-2026-24781

vm2 Node.js sandbox allows attackers to run commands on your system

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the VM2 sandboxing tool to escape security boundaries and execute unauthorized commands. This could lead to a full server compromise, granting the attacker access to sensitive business files and credentials.

CVE advisoryCRITICAL

CVE-2026-24120

vm2 sandbox escape allows attackers to run any command on your system

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the vm2 sandbox to bypass its security, allowing them to run unauthorized commands on the host server. This could lead to a complete system compromise, granting the attacker access to sensitive business data and administrative control.

CVE advisoryCRITICAL

CVE-2026-24118

vm2 Node.js sandbox escape allows attackers to run commands on your system

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the vm2 software to bypass its security protections and take control of your host server. This could lead to a total system compromise, potentially exposing sensitive credentials and files stored on your infrastructure.

CVE advisoryCRITICAL

CVE-2025-70067

Assimp FBX Importer could allow external attacker to take control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can take control of systems using the Assimp library by providing a maliciously crafted 3D model file. If opened, this allows the attacker to run unauthorized code on the host system, potentially leading to a complete compromise of the affected application.

CVE advisoryCRITICAL

CVE-2026-7161

GeoVision GV-IP Device Utility could allow internal attacker to steal credentials and gain control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker on your local network could intercept GeoVision GV-IP Device Utility traffic to steal device passwords. This unauthorized access allows them to take full control of your hardware, enabling them to alter security configurations or reset devices to factory settings.