NVD disclosure day

Published threat advisories for May 11, 2026

CVE advisoryCRITICAL

CVE-2026-43899

DeepChat could allow external attacker to take full control of systems.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a security flaw in the DeepChat AI platform to run unauthorized commands on a user's computer. This could result in a full system compromise when a user interacts with a malicious link generated by an untrusted AI response.

CVE advisoryCRITICAL

CVE-2026-7813

pgAdmin 4 could allow an internal attacker to steal credentials and run unauthorized commands.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with a pgAdmin 4 account can exploit this flaw to steal sensitive database credentials and view private server data. This could allow unauthorized access to database systems and facilitate a full compromise of internal business information.

CVE advisoryHIGH

CVE-2025-9973

WSO2 Identity Server allows attackers to access other companies' data by misusing authentication rules.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit WSO2 Identity Server to gain unauthorized access to other organizations' accounts by manipulating authentication logic. This matters because it could lead to account takeover and access to sensitive information.

CVE advisoryHIGH

CVE-2025-10470

WSO2 Identity Server can be taken offline by attackers sending too many bad login attempts.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

WSO2 Identity Server can be taken offline by attackers sending too many bad login attempts. This vulnerability directly impacts service availability for users, especially for those relying on the Magic Link authentication method.

CVE advisoryCRITICAL

CVE-2026-35157

Dell ECS and ObjectScale could allow an external attacker to take control of systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in Dell ECS and ObjectScale by injecting malicious strings into data that the application includes in reports. If a user opens these generated files, the attacker could gain unauthorized command execution, potentially compromising stored data and credentials.