NVD disclosure day

Published threat advisories for May 7, 2026

CVE advisoryCRITICAL

CVE-2026-42880

Argo CD could allow internal attacker to expose sensitive system secrets

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with limited access can exploit a flaw in Argo CD to steal sensitive system credentials. This vulnerability could allow them to impersonate trusted accounts and gain unauthorized control over critical cloud infrastructure.

CVE advisoryCRITICAL

CVE-2026-33844

Azure Managed Instance for Apache Cassandra could allow internal attacker to run unauthorized code.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing access to Azure Managed Instance for Apache Cassandra could run unauthorized code. This allows them to change system settings or access sensitive application data, potentially compromising the entire database environment.

CVE advisoryCRITICAL

CVE-2026-33109

Azure Managed Instance for Cassandra could allow internal attacker to execute unauthorized code

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with network access could exploit a flaw in Azure Managed Instance for Apache Cassandra to run unauthorized commands. This could allow them to take control of the service and potentially gain access to sensitive business data.

CVE advisoryCRITICAL

CVE-2026-37709

Snipe-IT allows attackers to run any code, potentially stealing data or disrupting service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in the Snipe-IT asset management system to remotely run unauthorized commands on the server. This could lead to a full compromise of the system and exposure of sensitive corporate asset inventory data.

CVE advisoryCRITICAL

CVE-2026-7414

Yarbo lawn mowers have easy-to-guess passwords letting attackers control them.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Yarbo firmware uses identical, unchangeable administrative passwords that allow an external attacker to bypass security and gain management access. This enables full administrative control over the device, risking unauthorized configuration changes and the theft of sensitive data.

CVE advisoryCRITICAL

CVE-2026-7413

Yarbo lawn mowers have a hidden backdoor that attackers can use to take control of your devices remotely.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A hidden backdoor in Yarbo firmware allows an external attacker to bypass security measures and take full control of the device over the internet. This creates a severe business risk, as the flaw is persistent and could allow unauthorized parties to establish permanent, undetected access to your infrastructure.

CVE advisoryCRITICAL

CVE-2026-5787

Attacker can impersonate Ivanti EPMM servers to steal client certificates.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An attacker can impersonate Ivanti EPMM servers to steal legitimate client certificates, potentially compromising sensitive data and mobile device management. This is a critical vulnerability due to its internet-facing exposure and unauthenticated remote attack possibility.

CVE advisoryCRITICAL

CVE-2025-63703

npm package parse-ini allows attackers to take control of applications

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit the parse-ini library to manipulate application data and behavior, potentially bypassing security controls to gain unauthorized access. This could lead to sensitive information exposure or unauthorized changes to core business functions.

CVE advisoryCRITICAL

CVE-2025-63706

next-npm-version could allow external attacker to gain full control of servers

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The next-npm-version package contains a flaw that allows an external attacker to execute unauthorized commands on host servers. This exposure could grant the attacker access to sensitive environment variables, proprietary source code, or control over the application environment.

CVE advisoryCRITICAL

CVE-2026-6795

DivvyDrive lets attackers redirect users to malicious sites to steal data or control accounts.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An external attacker can exploit a flaw in DivvyDrive to redirect users to malicious websites, increasing the success of phishing campaigns. This facilitates the theft of sensitive user credentials and session tokens, which could lead to unauthorized access to company accounts.

CVE advisoryCRITICAL

CVE-2026-30496

Attacker can remotely control Optoma projectors to change settings or disable network features.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker on the local network can gain full remote control over the Optoma CinemaX P2 projector due to missing security checks. This could allow unauthorized changes to projector settings and enable further access into your network, potentially disrupting business operations.

CVE advisoryCRITICAL

CVE-2026-8094

Firefox and Thunderbird could allow an external attacker to compromise the browser

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a vulnerability in the Firefox ESR and Thunderbird media processing component to take control of a user's browser. This could allow them to steal sensitive data or install malicious software, posing a risk to both user workstations and company information.

CVE advisoryCRITICAL

CVE-2026-6508

Liderahenk could allow an attacker unauthorized control and access to sensitive data.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker could exploit a flaw in Liderahenk to bypass security checks and access restricted management functions. This allows them to manipulate system configurations, potentially resulting in full administrative control over connected infrastructure.

CVE advisoryCRITICAL

CVE-2025-1978

Attacker can gain full control of Hitachi storage systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit a flaw in Hitachi Storage Navigator to gain control of critical storage systems, potentially resulting in data loss or operational disruption. This vulnerability allows unauthorized commands to be run on the hardware, creating a significant risk to business operations.

CVE advisoryCRITICAL

CVE-2026-41586

Hyperledger Fabric flaw could allow attackers to take control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a flaw in Hyperledger Fabric to gain administrative control over the platform. This creates a severe business risk, as it allows unauthorized access to sensitive data and could lead to the compromise of ledger integrity or total operational failure.