NVD disclosure day

Published threat advisories for May 5, 2026

CVE advisoryCRITICAL

CVE-2026-28780

Apache HTTP Server can be hijacked to take over systems or expose sensitive files

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Apache HTTP Server contains a flaw that allows an internal attacker to send malicious data, potentially causing a system crash or full server compromise. This vulnerability could lead to critical service outages and unauthorized access to sensitive systems.

CVE advisoryCRITICAL

CVE-2026-38429

OpenCMS allows attackers to steal sensitive files or take control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenCMS allows an internal attacker with administrative access to view sensitive server files by uploading a malicious file through the file import tool. This exposure could reveal system credentials or configuration data, which may be used to compromise the entire server.

CVE advisoryCRITICAL

CVE-2026-7411

Eclipse BaSyx allows attackers to overwrite files and take control of systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a file upload vulnerability in the Eclipse BaSyx Java Server SDK to place malicious files on the server. This allows them to run unauthorized code, resulting in a complete loss of control over the system and the data it manages.

CVE advisoryCRITICAL

CVE-2026-34002

X.Org X server could allow internal attacker to expose sensitive data or cause crashes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in the X.Org X server to access private data or force a system crash. This allows unauthorized access to sensitive information like credentials and can disrupt key desktop operations, posing a risk to data security and workflow continuity.

CVE advisoryCRITICAL

CVE-2023-54344

Eclipse Equinox OSGi allows attackers to run any command, potentially taking control of systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit the Eclipse Equinox OSGi management console to seize full control of the system without authentication. This allows them to steal sensitive data and gain a permanent foothold, compromising the security of business applications.

CVE advisoryCRITICAL

CVE-2023-54342

Eclipse Equinox OSGi allows attackers to take control of systems over the internet

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the Eclipse Equinox OSGi console to run unauthorized software on the host. This allows them to gain full control of the system, risking unauthorized access to sensitive files and customer data.