NVD disclosure day

Published threat advisories for May 12, 2026

CVE advisoryCRITICAL

CVE-2026-42288

ChurchCRM could allow an external attacker to take control of the server.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

By targeting the setup wizard in ChurchCRM, an external attacker can gain complete control over the host server. This allows the attacker to steal sensitive member data or maintain unauthorized, long-term access to the organization's infrastructure.

CVE advisoryCRITICAL

CVE-2026-44015

Nginx UI flaw lets attackers access internal systems and sensitive data.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with access to Nginx UI can manipulate system settings to bypass network security controls. This allows them to interact with restricted internal services, potentially exposing critical configuration files or private business data.

CVE advisoryCRITICAL

CVE-2026-42854

Attacker can crash devices or run code using Arduino-ESP32 web server

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can send a malicious web request to an Arduino ESP32 device, potentially gaining full control over the unit and its connected hardware. This creates a significant risk to the security and operational reliability of any internet-connected system using this technology.

CVE advisoryCRITICAL

CVE-2026-45185

Exim mail servers can be remotely hijacked to run any code.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Exim mail servers have a critical flaw that allows attackers to take complete control of your systems without needing any login. This serious vulnerability affects how Exim handles certain email transfers, making it a prime target for immediate attention.

CVE advisoryCRITICAL

CVE-2026-44225

Pulpy could allow internal attacker to steal sensitive credentials and files.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Pulpy contains a security flaw allowing an internal attacker to bypass access restrictions and steal sensitive data, such as SSH keys and cloud credentials. This could lead to unauthorized access to critical systems and compromise your organization's remote infrastructure.

CVE advisoryCRITICAL

CVE-2026-44221

ArcadeDB could allow internal attacker to access and modify data in unauthorized databases.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with limited ArcadeDB credentials can bypass security controls to read, change, or delete data in any database on the server. This flaw allows unauthorized access to sensitive company information and could result in the loss of administrative control over the entire database system.

CVE advisoryCRITICAL

CVE-2026-8431

MongoDB Ops Manager could allow internal attacker to gain full control of the server.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to MongoDB Ops Manager can manipulate webhook settings to execute unauthorized commands. This could allow them to gain full control of the server, potentially exposing critical infrastructure and sensitive management systems to compromise.

CVE advisoryCRITICAL

CVE-2026-34659

Adobe Connect could allow an external attacker to run unauthorized code

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit Adobe Connect by luring users to malicious links, allowing them to run unauthorized code on the user's computer. This could lead to the theft of sensitive meeting materials and confidential company communications.

CVE advisoryCRITICAL

CVE-2026-44183

Attacker can gain administrator control of Cleanuparr by faking network access.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Cleanuparr to bypass security and gain full administrative access by spoofing network requests. This allows them to modify automation settings, manipulate connected download clients, or delete files without authorization.

CVE advisoryCRITICAL

CVE-2026-42898

Microsoft Dynamics 365 (on-premises) could allow internal attacker to gain control of the server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a flaw in Microsoft Dynamics 365 (on-premises) to run unauthorized code on the server, potentially gaining full administrative control. This could result in the theft of sensitive business data and allow further movement within the company network.

CVE advisoryCRITICAL

CVE-2026-42833

Microsoft Dynamics 365 (on-premises) could allow an internal attacker to run system commands.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Microsoft Dynamics 365 (on-premises) contains a flaw that allows an internal attacker to run unauthorized system commands. This risk could enable them to gain full administrative control over the application server and access sensitive enterprise data.

CVE advisoryCRITICAL

CVE-2026-42823

Azure Logic Apps could allow an internal attacker to elevate their access privileges.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with existing access to Azure Logic Apps could manipulate the system to grant themselves unauthorized permissions. This allows them to disable critical business automations, potentially compromising sensitive data and gaining control over connected systems.

CVE advisoryCRITICAL

CVE-2026-41096

Microsoft Windows DNS could allow an external attacker to take control of servers

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can send malicious network traffic to the Microsoft Windows DNS service to gain full control of the affected server. Since this service is fundamental to network communication, a breach could allow unauthorized access to critical systems and sensitive company information.

CVE advisoryCRITICAL

CVE-2026-41089

Windows Netlogon could allow an external attacker to take control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in Windows Netlogon to steal administrative credentials and move through the network. This risk could result in a complete business disruption and unauthorized access to your company’s entire digital environment.

CVE advisoryHIGH

CVE-2026-40361

Microsoft Office Local Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory management flaw in Microsoft Office allows an unauthorized attacker to execute code locally on affected systems, potentially leading to data compromise and business disruption. This vulnerability impacts various Microsoft Office products. The risk is classified as internal, meaning exploitation typically requi

CVE advisoryCRITICAL

CVE-2026-33821

Microsoft Dynamics 365 Customer Insights could allow an internal attacker to gain higher access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with basic Microsoft Dynamics 365 Customer Insights access could trick the system to gain administrative privileges. This allows them to access sensitive customer data and manipulate critical business settings, potentially compromising proprietary information.

CVE advisoryCRITICAL

CVE-2026-31239

Mamba framework could allow external attacker to take control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Mamba language model framework allows an external attacker to compromise systems if a developer downloads a compromised pre-trained model. This flaw lets the attacker run unauthorized software, which could lead to the theft of sensitive company data and credentials.

CVE advisoryCRITICAL

CVE-2026-31237

Ludwig framework lets attackers run any code on your systems by uploading a file.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Ludwig framework contains a security flaw that allows an external attacker to run unauthorized commands on your system by providing a malicious data file. This can lead to a full system compromise, granting them control over your infrastructure and access to sensitive files.

CVE advisoryCRITICAL

CVE-2026-31235

Imgaug library could allow an internal attacker to execute malicious code.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Imgaug library contains a flaw that allows an internal attacker to run unauthorized code on host systems. By manipulating shared data, they could take control of the system, potentially accessing sensitive files or establishing long-term access.

CVE advisoryCRITICAL

CVE-2026-31233

Guardrails AI could allow internal attacker to execute malicious code on systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security flaw in Guardrails AI could allow an internal attacker to execute malicious code during package installations. This could lead to stolen credentials, exposed source code, and unauthorized control over developer workstations and connected environments.

CVE advisoryCRITICAL

CVE-2026-31230

Adversarial Robustness Toolbox could allow an internal attacker to execute unauthorized code

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a flaw in the Adversarial Robustness Toolbox to gain control of the application. This could lead to a full system compromise, providing them with unauthorized administrative access to the machine learning evaluation environment.

CVE advisoryCRITICAL

CVE-2026-20794

Intel Graphics Driver could allow internal attacker to gain admin access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker could exploit a flaw in the Intel Graphics Driver for VMware ESXi to gain administrative access, potentially compromising the confidentiality, integrity, and availability of critical system components. This matters to the business as it could lead to unauthorized control over sensitive data and es…

CVE advisoryCRITICAL

CVE-2025-65719

Kubectl MCP Server could allow an external attacker to gain full control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can target the Open Source Kubectl MCP Server by tricking users into visiting a malicious webpage. This flaw allows the attacker to execute unauthorized commands, potentially leading to full administrative access over connected Kubernetes clusters and exposing sensitive infrastructure data.

CVE advisoryCRITICAL

CVE-2026-31228

Adversarial Robustness Toolbox could allow an external attacker to gain full system control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit a flaw in the Adversarial Robustness Toolbox by providing malicious model configuration parameters. This allows them to execute unauthorized commands on the underlying system, leading to full control and unauthorized access to valuable model data.

CVE advisoryCRITICAL

CVE-2026-31226

TinyZero could allow internal attacker to run unauthorized system commands

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

TinyZero has a security flaw that allows an internal attacker to execute unauthorized system commands by supplying malicious file paths. This could lead to a complete compromise of the underlying host, enabling access to sensitive training data and environment secrets.

CVE advisoryCRITICAL

CVE-2026-31220

Attacker can take full control of servers through PySyft code execution flaw

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit the PySyft platform by submitting malicious code to gain complete control over the server. This flaw creates a severe risk, enabling unauthorized access to sensitive data and a full compromise of the hosting environment.

CVE advisoryCRITICAL

CVE-2026-31217

Optimate could allow an internal attacker to take full control of the system.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in Optimate to gain full control of the system by processing malicious files. This unauthorized access allows them to steal sensitive environment variables, source code, and internal resources, threatening critical business operations.

CVE advisoryCRITICAL

CVE-2026-8401

Firefox could allow external attacker to compromise the computer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can compromise a Firefox user's workstation by luring them to a malicious website that exploits a flaw in the browser's profile backup process. This allows the attacker to steal private user data or install malicious software, potentially leading to a full system takeover.

CVE advisoryCRITICAL

CVE-2026-8043

Ivanti Xtraction could allow internal attacker to read sensitive files

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with valid system access can exploit a file handling flaw in Ivanti Xtraction to read sensitive data or inject malicious scripts. This could result in the theft of confidential information and hijacked user sessions, directly compromising the security of company data.

CVE advisoryCRITICAL

CVE-2026-45091

sealed-env could allow internal attacker to expose authentication secrets

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The sealed-env library mistakenly exposes sensitive authentication codes in application logs and system dumps. An internal attacker can steal these credentials to bypass multi-factor security and gain unauthorized administrative control over sensitive internal systems.

CVE advisoryCRITICAL

CVE-2026-8072

Ingecon Sun EMS Board could allow an internal attacker to obtain admin credentials.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with local access to an Ingecon Sun EMS Board could exploit a flaw to bypass login security and obtain administrative credentials. This would allow them to change device settings and gain full control over the energy management infrastructure.

CVE advisoryCRITICAL

CVE-2026-7428

Google Cloud AlloyDB could allow an external attacker to gain full administrative database access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Databases created in Google Cloud AlloyDB for PostgreSQL using automation may contain insecure default passwords, allowing an external attacker to gain full administrative access. This could let unauthorized users steal sensitive business data and compromise your systems.

CVE advisoryCRITICAL

CVE-2026-25787

Siemens motion control devices could allow internal attacker to hijack user sessions.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to Siemens motion control devices can exploit a software flaw to hijack other users' web sessions. This allows them to perform unauthorized administrative actions, potentially leading to modified system configurations or the disruption of critical industrial operations.

CVE advisoryCRITICAL

CVE-2026-25786

Siemens PLCs could allow internal attacker to compromise user web sessions.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Siemens PLCs have a flaw allowing an internal attacker to inject code into the web interface. If a legitimate user accesses the device, the attacker can hijack their session to modify critical operational settings or gain unauthorized control over the industrial system.

CVE advisoryCRITICAL

CVE-2026-41872

Kura Sushi Official App could allow an external attacker to read or tamper with notifications.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a security flaw in the Kura Sushi Official App to intercept or manipulate push notifications. This could allow attackers to send deceptive messages or phishing links to customers, potentially leading to unauthorized access to sensitive account information.

CVE advisoryCRITICAL

CVE-2026-34260

SAP S/4HANA could allow internal attacker to access sensitive data or crash the system.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with access to the SAP S/4HANA enterprise search feature can manipulate the system to view restricted business data or cause service crashes. This risks exposing sensitive organizational information and interrupting essential business operations.

CVE advisoryHIGH

CVE-2026-45393

I cannot generate a risk brief because the details for CVE-2026-45393 are currently reserved and not yet publicly disclosed.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit a flaw in Cribl Edge to potentially intercept sensitive data or alter data routing. This could lead to unauthorized access to company telemetry, large-scale data exfiltration, or the subversion of internal security monitoring systems.

CVE advisoryHIGH

CVE-2026-45392

Unable to generate: The provided CVE description is reserved and contains no information regarding the specific business impact.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could potentially exploit a vulnerability in Cribl Stream to compromise critical data pipelines and sensitive logs. Because vulnerability details are currently reserved, the specific risk to business operations and system security remains uncertain.

CVE advisoryHIGH

CVE-2026-45391

Cannot generate title: CVE-2026-45391 is reserved and lacks public impact details.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could potentially exploit an undisclosed vulnerability in the Cribl Edge platform. While the specific technical impact remains unknown due to the lack of public disclosure, this flaw poses a risk to the sensitive observability data managed by the system.

CVE advisoryKnown Exploit

CVE-2026-45321

TanStack Packages Compromised via npm Supply Chain Attack

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Malicious versions of @tanstack/* packages were published to the npm registry through a supply chain attack, leveraging GitHub Actions vulnerabilities to steal credentials and distribute malware. This impacts multiple TanStack products, potentially allowing for significant data compromise.

• CISA KEV