NVD disclosure day

Published threat advisories for May 6, 2026

CVE advisoryCRITICAL

CVE-2026-43578

OpenClaw could allow an internal attacker to gain unauthorized administrative access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing access can manipulate background processes within OpenClaw to bypass intended security settings. This could allow them to gain elevated permissions and obtain full administrative control over the system.

CVE advisoryCRITICAL

CVE-2026-7910

Google Chrome could allow an external attacker to access sensitive data from other websites.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in Google Chrome to bypass security protections that keep website data separate. This could allow them to steal sensitive information or user credentials when a user visits a malicious website.

CVE advisoryCRITICAL

CVE-2026-7908

Google Chrome could allow external attacker to take control of the computer.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in the Google Chrome browser by tricking a user into visiting a malicious website. This allows the attacker to bypass built-in security to run code and gain full administrative control over an employee's computer.

CVE advisoryCRITICAL

CVE-2026-41930

Vvveb database accessible to attackers for stealing customer data and admin passwords

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Vvveb uses preset database passwords that allow an external attacker to access the system's management interface. This exposes sensitive customer information and administrator accounts to theft or manipulation, risking complete application compromise.

CVE advisoryKnown Exploit

CVE-2026-0300

Palo Alto firewalls can be taken over by attackers remotely

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical flaw in Palo Alto firewalls' User-ID service allows attackers to gain full control of the device remotely without authentication. This vulnerability warrants immediate attention due to its potential for widespread network compromise.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-29080

Attacker can steal customer data or gain admin control of Rucio

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a flaw in the Rucio platform to gain full database access. This allows them to steal sensitive information such as account credentials and proprietary data, risking a total compromise of the system’s managed information.

CVE advisoryCRITICAL

CVE-2026-5081

Apache session IDs can be guessed allowing attackers to take control of user accounts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in Apache::Session::Generate::ModUniqueId can allow attackers to guess session IDs, potentially letting them take over user accounts in web applications. This issue deserves attention now as it affects internet-facing applications and could lead to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-43197

Linux kernel netconsole could allow internal attacker to crash the system

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing system access could exploit a flaw in the Linux kernel's logging component to crash the system or steal sensitive information like cryptographic keys. This risk is significant as it could lead to unauthorized data exposure and unplanned business downtime.

CVE advisoryCRITICAL

CVE-2026-43185

Linux kernel flaw lets attackers gain control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can send malicious requests to the Linux file sharing service, potentially causing system crashes or granting them full control over the server. This poses a significant risk by enabling unauthorized access to the operating system and disrupting critical business operations.

CVE advisoryCRITICAL

CVE-2026-43125

Linux kernel cluster software could allow internal attacker to compromise servers

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker could exploit a flaw in the Linux kernel to crash servers or gain full system control by sending malformed network messages. This risks critical business disruptions and the loss of essential infrastructure availability.

CVE advisoryCRITICAL

CVE-2025-59852

HCL DFXAnalytics allows attackers to steal sensitive data without encryption.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

HCL DFXAnalytics transmits information without encryption, allowing an external attacker to intercept network traffic and steal login credentials. This exposes sensitive data and could allow unauthorized parties to gain administrative control over the application.

CVE advisoryCRITICAL

CVE-2026-43117

Linux kernel btrfs could allow internal attacker to crash the system

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing system access can exploit a vulnerability in the Linux kernel’s Btrfs storage component to trigger an unrecoverable system crash. This could cause unexpected service outages and disrupt critical business operations reliant on this storage technology.

CVE advisoryCRITICAL

CVE-2026-43114

Linux kernel could allow internal attacker to bypass firewall rules

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security flaw in the Linux kernel firewall could allow an internal attacker with existing administrative privileges to manipulate network rules and bypass security policies. This could lead to unauthorized access to sensitive network services or hosts.