NVD disclosure day

Published threat advisories for May 15, 2026

CVE advisoryCRITICAL

CVE-2026-44566

Open WebUI could allow an internal attacker to write unauthorized files to the system

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can manipulate file uploads in Open WebUI to save malicious files to restricted system locations. This could allow them to override critical settings or run unauthorized code, leading to a complete compromise of the platform.

CVE advisoryCRITICAL

CVE-2026-46364

phpMyFAQ's public API can expose customer data due to SQL injection.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

phpMyFAQ's public API is vulnerable to SQL injection, potentially exposing sensitive customer data like credentials to unauthenticated attackers. This advisory deserves attention now due to the direct exposure of customer data and ease of exploitation.

CVE advisoryCRITICAL

CVE-2026-45035

Tabby could allow an external attacker to take control of a user's computer.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Tabby contains a flaw that allows an external attacker to compromise a user’s computer through a malicious link. If clicked, the attacker can run unauthorized commands, potentially leading to the theft of sensitive local files or complete control of the workstation.

CVE advisoryCRITICAL

CVE-2026-44717

MCP Calculate Server lets attackers take control or disrupt services by sending bad math.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

MCP Calculate Server contains a vulnerability that allows an external attacker to run malicious commands on the server by sending crafted mathematical queries. This could lead to a full system compromise, granting the attacker control over the server and unauthorized access to business data.

CVE advisoryCRITICAL

CVE-2026-42155

Magento security flaw lets attackers hijack sessions to steal customer data or disrupt service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A security flaw in Magento LTS allows attackers to easily hijack active sessions, potentially accessing sensitive customer data or disrupting your online store. This is a critical vulnerability affecting internet-facing APIs.

CVE advisoryCRITICAL

CVE-2026-41258

OpenMRS could allow internal attacker to gain unauthorized system control.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with specific administrative privileges could exploit a vulnerability in OpenMRS to run unauthorized code. This could allow them to gain full system control and access sensitive patient data, creating a severe risk to data privacy and platform integrity.

CVE advisoryKnown Exploit

CVE-2026-8398

Supply Chain Attack on DAEMON Tools Lite Compromises Installation Packages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Official DAEMON Tools Lite installation packages were compromised through a supply chain attack, embedding trojanized binaries signed with legitimate certificates. This allows malicious code to appear trustworthy, potentially leading to unauthorized system access and control when users install the affected software. It

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-0481

AMD Device Metrics Exporter could allow an external attacker to cause GPU availability loss.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can modify GPU configurations in the AMD Device Metrics Exporter. This allows them to disable device features, which could cause outages for GPU-dependent applications and disrupt critical computing workloads.