NVD disclosure day

Published threat advisories for May 18, 2026

CVE advisoryCRITICAL

CVE-2026-8838

Amazon Redshift Python driver could allow external attacker to take control of user systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can use the Amazon Redshift Python driver to gain unauthorized control of a user's system by tricking it into connecting to a malicious database. This exposes the organization to a full system takeover and the loss of sensitive data.

CVE advisoryCRITICAL

CVE-2026-25244

WebdriverIO could allow external attacker to steal credentials and compromise build systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit WebdriverIO by using a malicious repository to run unauthorized code on CI/CD servers or developer machines. This could lead to the theft of sensitive credentials, source code, and secrets, potentially resulting in a compromise of your build systems.

CVE advisoryCRITICAL

CVE-2026-8836

Attacker can gain control of systems using lwIP via network access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can take advantage of a flaw in lwIP network software to gain unauthorized control over devices or cause system outages. This vulnerability creates a risk of full system compromise, potentially disrupting critical operations and essential connectivity.

CVE advisoryCRITICAL

CVE-2026-42822

Azure vulnerability lets attackers steal control of systems over the network

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Azure Local has a flaw in its disconnected operations feature that allows an external attacker to bypass security checks and gain administrative control. This could enable them to modify sensitive system configurations or create unauthorized accounts, potentially compromising critical business infrastructure.

CVE advisoryCRITICAL

CVE-2026-45829

ChromaDB allows attackers to run any code on your server.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a vulnerability in the ChromaDB service to gain full control of the server without requiring credentials. This flaw puts business operations at significant risk by enabling the theft of sensitive data and the disruption of critical database services.

CVE advisoryCRITICAL

CVE-2026-41948

Dify systems can be taken over by attackers due to flaws in how they handle requests.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dify versions prior to 1.14.1 have a critical flaw allowing authenticated users to access internal systems by manipulating file paths, potentially exposing sensitive data. The platform's easy self-registration for Dify Cloud makes it accessible to anyone.

CVE advisoryCRITICAL

CVE-2026-7302

SGLangs allows attackers to write anywhere on your systems without logging in.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a file upload flaw in SGLang to overwrite critical system files and seize control of the server. This poses a severe risk of a total loss of system integrity and could lead to further unauthorized activity across the business network.