NVD disclosure day

Published threat advisories for May 9, 2026

CVE advisoryCRITICAL

CVE-2026-42571

Pelican could allow internal attacker to gain unauthorized administrative access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Pelican allows an internal attacker with a standard account to gain full administrative privileges. This enables unauthorized modification of sensitive system settings and access to restricted data, effectively compromising the platform.

CVE advisoryCRITICAL

CVE-2026-6665

PgBouncer could allow internal attacker to cause system crashes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with control over a connected database can crash the PgBouncer service or compromise the server by sending malformed data. This poses a risk to database availability and could disrupt critical business operations that rely on this connection tool.

CVE advisoryCRITICAL

CVE-2026-44313

Authenticated users can steal sensitive data or disrupt Linkwarden services

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with access to Linkwarden can force the software to connect to private internal services that should be inaccessible. This could lead to unauthorized access to sensitive business data or allow the attacker to probe other internal systems.