NVD disclosure day

Published threat advisories for May 5, 2026

CVE advisoryCRITICAL

CVE-2026-28780

Apache HTTP Server can be hijacked to take over systems or expose sensitive files

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Apache HTTP Server contains a flaw that allows an internal attacker to send malicious data, potentially causing a system crash or full server compromise. This vulnerability could lead to critical service outages and unauthorized access to sensitive systems.

CVE advisoryCRITICAL

CVE-2026-33324

SQLBot lets attackers steal data or take control by manipulating database queries.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can manipulate SQLBot’s chat interface to execute unauthorized commands on the underlying database server. This could allow them to take full control of the server and compromise sensitive company data.

CVE advisoryCRITICAL

CVE-2026-38428

Attackers can steal customer data or control Kestra systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can manipulate the database in the Kestra platform by sending malicious web requests. This could allow unauthorized access to sensitive business workflows, system configurations, and stored credentials, putting proprietary data at risk.

CVE advisoryCRITICAL

CVE-2026-38431

ERPNext email templates allow attackers to take control of your server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with email template editing rights can run unauthorized commands to gain full control of the ERPNext server. This enables them to steal sensitive business data and compromise the core systems that support daily operations.

CVE advisoryCRITICAL

CVE-2026-38429

OpenCMS allows attackers to steal sensitive files or take control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenCMS allows an internal attacker with administrative access to view sensitive server files by uploading a malicious file through the file import tool. This exposure could reveal system credentials or configuration data, which may be used to compromise the entire server.

CVE advisoryCRITICAL

CVE-2026-7411

Eclipse BaSyx allows attackers to overwrite files and take control of systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a file upload vulnerability in the Eclipse BaSyx Java Server SDK to place malicious files on the server. This allows them to run unauthorized code, resulting in a complete loss of control over the system and the data it manages.

CVE advisoryCRITICAL

CVE-2026-43067

Linux ext4 file system could allow internal attacker to corrupt system data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing system access could manipulate the Linux ext4 file system to corrupt data or cause a system crash. This could result in the loss of data integrity and the disruption of critical server operations.

CVE advisoryCRITICAL

CVE-2026-34002

X.Org X server could allow internal attacker to expose sensitive data or cause crashes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in the X.Org X server to access private data or force a system crash. This allows unauthorized access to sensitive information like credentials and can disrupt key desktop operations, posing a risk to data security and workflow continuity.

CVE advisoryCRITICAL

CVE-2023-54344

Eclipse Equinox OSGi allows attackers to run any command, potentially taking control of systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit the Eclipse Equinox OSGi management console to seize full control of the system without authentication. This allows them to steal sensitive data and gain a permanent foothold, compromising the security of business applications.

CVE advisoryCRITICAL

CVE-2023-54342

Eclipse Equinox OSGi allows attackers to take control of systems over the internet

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in the Eclipse Equinox OSGi console to run unauthorized software on the host. This allows them to gain full control of the system, risking unauthorized access to sensitive files and customer data.