NVD disclosure day

Published threat advisories for May 14, 2026

CVE advisoryCRITICAL

CVE-2026-8580

Google Chrome could allow an external attacker to gain access to your computer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can compromise a user's computer running Google Chrome by tricking them into visiting a malicious website. This flaw lets them bypass security protections to run unauthorized code and potentially steal sensitive files, leading to a full system compromise.

CVE advisoryCRITICAL

CVE-2026-8511

Google Chrome could allow external attacker to take control of user computers

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Google Chrome by enticing users to visit a malicious website. This allows them to bypass security protections and potentially gain full control over user computers to steal sensitive data or install malicious programs.

CVE advisoryCRITICAL

CVE-2026-44592

Gradient CI can be controlled by anyone who can reach it, allowing them to upload any files.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in Gradient to register unauthorized systems, granting them access to sensitive job data. This allows them to inject malicious code, which could compromise the integrity of the company's software supply chain.

CVE advisoryCRITICAL

CVE-2026-41315

Attacker can take over your systems by exploiting an unprotected command execution flaw in mdserver-web

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in mdserver-web allows anyone to take over your systems remotely by executing commands without any login. This issue is urgent because it's easy to exploit and can give attackers full control.

CVE advisoryCRITICAL

CVE-2026-22599

Strapi could allow internal attacker to access sensitive database files or crash systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to Strapi could use a flaw in its management tools to run unauthorized database commands. This allows them to steal sensitive files, crash systems, or gain full control over the database infrastructure.

CVE advisoryCRITICAL

CVE-2026-46470

GStreamer audio processing allows attackers to crash services processing MP4 files

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could crash applications using GStreamer by submitting a malicious MP4 audio file. This interruption prevents media services from functioning, resulting in service outages that stop users from accessing content.

CVE advisoryKnown Exploit

CVE-2026-42897

Microsoft Exchange Server Spoofing Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server is affected by a cross-site scripting vulnerability that can allow unauthorized network spoofing. This presents a risk of unauthorized actions and data manipulation, impacting organizations and their employees. Organizations should apply vendor mitigations promptly.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-42555

Valtimo could allow an internal attacker to take control of systems and steal credentials.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with administrative access to the Valtimo platform could seize control of company systems and steal sensitive credentials. This puts confidential documents and business data at risk of unauthorized access or manipulation.

CVE advisoryKnown Exploit

CVE-2026-20182

Attackers can gain admin control of Cisco SD-WAN systems

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker can bypass security controls on Cisco Catalyst SD-WAN systems to gain administrative privileges and alter network configurations. This advisory warrants immediate attention due to potential for broad network control compromise.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-42589

Attacker can take control of Gotenberg servers processing PDFs via unauthenticated commands.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Gotenberg servers processing PDFs can be fully controlled by attackers through a single unauthenticated request, allowing them to run any command on the server. This critical flaw affects versions prior to 8.31.0 and is easily exploitable over the network.

CVE advisoryCRITICAL

CVE-2026-42281

MagicMirror² could allow external attacker to steal server secrets and access internal systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can manipulate MagicMirror² to probe private network resources and steal sensitive server credentials. This exposes confidential information and potentially allows unauthorized access to internal business systems.

CVE advisoryCRITICAL

CVE-2026-44484

PyTorch Lightning could allow internal attacker to steal sensitive credentials

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

PyTorch Lightning contains a flaw that permits an internal attacker to covertly capture authentication materials when users run model training or fine-tuning scripts. This access could lead to unauthorized control over cloud environments and sensitive company resources.

CVE advisoryCRITICAL

CVE-2026-44482

SoundCloud-RPC could allow an external attacker to execute commands on user computers.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in SoundCloud-RPC to gain control over a user's computer by manipulating track information. This allows the attacker to execute unauthorized commands, potentially leading to the theft of sensitive data or full system compromise.

CVE advisoryCRITICAL

CVE-2026-42457

vCluster Platform could allow an internal attacker to create an administrative account.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker using the vCluster Platform can inject harmful code into templates to take over an administrator’s session. This could allow them to create unauthorized administrative accounts and gain full, unrestricted control over the platform.

CVE advisoryCRITICAL

CVE-2026-6510

WordPress plugin flaw lets attackers steal admin access and control your site

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the InfusedWoo Pro WordPress plugin allows unauthenticated attackers to steal admin access and gain full control of your website. This issue is urgent due to the ease of exploitation and potential for complete site takeover.