NVD disclosure day

Published threat advisories for May 17, 2026

CVE advisoryCRITICAL

CVE-2026-8721

Perl passwords for encrypted files can be unexpectedly shortened, risking data access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Crypt::OpenSSL::PKCS12 handles passwords incorrectly, allowing an external attacker to weaken security and easily guess credentials. This flaw could lead to the theft of sensitive private keys or certificates, resulting in unauthorized access to protected business information.

CVE advisoryCRITICAL

CVE-2026-8507

Perl PKCS12 files can be manipulated by attackers to take control of systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Crypt::OpenSSL::PKCS12 contains a security flaw that allows an external attacker to seize control of systems that process specific cryptographic files. By submitting a malicious file, an attacker could run unauthorized code, potentially leading to the compromise of sensitive application data and the underlying server.

CVE advisoryCRITICAL

CVE-2018-25320

ACL Analytics could allow internal attacker to gain full system control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a vulnerability in ACL Analytics to run unauthorized commands with full administrative access. This allows them to take complete control of the system, posing a significant risk to the security of sensitive business data.