NVD disclosure day

Published threat advisories for May 13, 2026

CVE advisoryCRITICAL

CVE-2026-44194

OPNsense could allow an internal attacker to gain full system control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with management privileges could gain full control of OPNsense firewalls by entering malicious commands into user email fields. This allows them to bypass security settings, risking complete system compromise and the potential failure of network defenses.

CVE advisoryCRITICAL

CVE-2026-44193

OPNsense could allow an external attacker to take full control of the firewall.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker with administrative credentials could exploit OPNsense to gain full control over the firewall. This allows them to intercept network traffic and dismantle security defenses, putting the entire organization's internal network at risk.

CVE advisoryCRITICAL

CVE-2025-27851

Garmin WDU could allow an external attacker to take full administrative control.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could gain full administrative control of the Garmin WDU by tricking a user into visiting a malicious website. This could lead to unauthorized manipulation of maritime system functions and full operational control of the unit.

CVE advisoryCRITICAL

CVE-2026-44364

MISP Modules could allow an external attacker to modify user session data.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can trick a logged-in user of MISP Modules into unintentionally changing search parameters. This could allow the attacker to manipulate results, potentially leading to the misdirection or exposure of sensitive threat intelligence.

CVE advisoryCRITICAL

CVE-2026-44351

Attacker can bypass authentication on systems using fast-jwt to access customer data or gain admin control.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in fast-jwt allows attackers to forge authentication tokens, potentially granting them access to sensitive data or administrative control by bypassing security checks without needing any credentials.

CVE advisoryCRITICAL

CVE-2026-42584

Netty can be tricked into mishandling data leading to service disruption

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in Netty to confuse the application about which server response belongs to a specific request. This could allow them to hijack user sessions or access sensitive information by tricking the system into misinterpreting incoming data streams.

CVE advisoryCRITICAL

CVE-2026-42579

Attacker could gain control of services that process untrusted DNS data or hostnames with Netty.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the Netty framework by sending malicious network traffic to our applications. This could allow them to crash our services or gain unauthorized control over systems processing this data, potentially disrupting business operations.

CVE advisoryHIGH

CVE-2026-30905

Zoom Workplace VDI Plugin: Privilege Escalation Risk

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Zoom Workplace VDI Plugin for Windows Installer may allow an authenticated local user to escalate privileges. This could affect organizations by enabling unauthorized access to systems and data. The risk is associated with local access to the affected installer.

CVE advisoryKnown Exploit

CVE-2026-0257

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Authentication bypass vulnerabilities in Palo Alto Networks' PAN-OS software allow attackers to circumvent security measures and establish unauthorized VPN connections. This could lead to the compromise of network traffic and internal systems by granting attackers unauthorized network access.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-40621

ELECOM access points could allow internal attacker to manage device settings without login

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can bypass login screens on ELECOM wireless LAN access points to manage device settings without authorization. By gaining administrative control, they could tamper with network configurations or intercept sensitive business traffic.

CVE advisoryCRITICAL

CVE-2026-41050

Fleet Helm deployer could allow internal attacker to access secrets across all clusters

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Fleet allows an internal attacker with existing repository access to expose sensitive credentials stored across connected systems. This vulnerability risks significant data theft and could allow unauthorized control over critical business infrastructure.

CVE advisoryHIGH

CVE-2025-11159

Pentaho Data Integration could allow internal attacker to run malicious code

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to Pentaho Data Integration & Analytics could exploit a flaw in database connection settings to run malicious code. This could allow them to take full control of the host server and access sensitive information.