NVD disclosure day

Published threat advisories for May 19, 2026

CVE advisoryCRITICAL

CVE-2026-33642

Kitty could allow an internal attacker to run malicious code on user systems.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory vulnerability in the Kitty terminal emulator allows an internal attacker to run unauthorized code by sending malicious data to an active terminal window. This could grant the attacker full control over the terminal session and lead to complete compromise of the host system.

CVE advisoryHIGH

CVE-2026-47107

Windmill could allow internal attacker to gain administrative access to workspaces

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a configuration flaw in Windmill to modify system files during script execution. This enables them to intercept user credentials and gain unauthorized administrative access to workspaces, potentially compromising sensitive tenant data.

CVE advisoryCRITICAL

CVE-2026-31071

LalanaChami Pharmacy System data exposed including customer passwords and medical records

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the LalanaChami Pharmacy system allows anyone on the internet to steal customer data, including passwords and private medical records, and alter inventory. This needs immediate attention to protect sensitive information.

CVE advisoryCRITICAL

CVE-2026-44159

Unsupported Tyler Identity Local can be taken over by attackers

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Tyler Identity Local uses default passwords that can allow an internal attacker to gain full administrative control of the application. This could enable them to modify identity records, change system settings, or export sensitive user data, resulting in a total compromise of the identity management system.

CVE advisoryCRITICAL

CVE-2026-2586

GlassFish admin console lets attackers run commands on your server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with valid credentials can misuse the GlassFish administration console to run unauthorized system commands. This could allow them to gain full control over the server, leading to compromised data and potential long-term access to critical business systems.

CVE advisoryHIGH

CVE-2026-8975

Thunderbird could allow external attacker to take control of systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker could exploit a flaw in Thunderbird by sending a malicious email that, when opened, allows them to run unauthorized code on the computer. This could grant the attacker access to sensitive communications, private attachments, and login credentials, putting the entire system at risk.

CVE advisoryHIGH

CVE-2026-8973

Thunderbird could allow an external attacker to take control of your computer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Thunderbird contains a flaw that an external attacker can trigger by sending a malicious email, allowing them to take control of the user's computer. This poses a significant risk to sensitive business data, as it could enable attackers to install harmful software or access private files.

CVE advisoryCRITICAL

CVE-2026-8959

Firefox and Thunderbird could allow an external attacker to take control of your computer.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Firefox and Thunderbird by luring users to malicious websites or emails to bypass security safeguards. This allows them to run unauthorized code, giving them full control over your workstations and access to sensitive data.

CVE advisoryCRITICAL

CVE-2026-8956

Firefox and Thunderbird could allow an external attacker to gain control of the system.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit Firefox and Thunderbird by luring users to malicious sites or opening crafted files to trigger a memory error. This allows them to seize control of the browser to steal sensitive credentials or potentially compromise the entire system.

CVE advisoryCRITICAL

CVE-2026-8953

Firefox and Thunderbird could allow an external attacker to gain control of user computers.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a security weakness in Firefox and Thunderbird to bypass browser protections and take control of a user’s computer. This allows the attacker to steal sensitive information or install unauthorized software on the host system.

CVE advisoryCRITICAL

CVE-2026-8950

Firefox and Thunderbird could allow an external attacker to steal sensitive website data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit Firefox or Thunderbird to bypass security boundaries if a user visits a malicious website. This allows the attacker to steal sensitive session data or authentication tokens, potentially leading to unauthorized account takeover.

CVE advisoryCRITICAL

CVE-2026-8948

Firefox and Thunderbird could allow an external attacker to access private web data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in Firefox and Thunderbird to steal sensitive data and session information when a user visits a malicious website, potentially leading to unauthorized account access or the theft of private business credentials.

CVE advisoryCRITICAL

CVE-2026-47323

Apache Camel can be tricked into running unauthorized code or writing files via its integration features.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache Camel has a critical flaw allowing unauthenticated attackers to execute arbitrary code or write files on your systems through crafted HTTP requests. This needs immediate attention to protect your integrations.

CVE advisoryCRITICAL

CVE-2026-42097

Sparx Pro Cloud Server lets attackers steal data or control systems by bypassing login.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can bypass security controls in Sparx Pro Cloud Server to run unauthorized database commands. This exposes sensitive project information and credentials, which could lead to the loss of proprietary intellectual property.

CVE advisoryCRITICAL

CVE-2026-4883

WordPress Piotnet Forms plugin allows attackers to upload dangerous files, potentially leading to remote code execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Piotnet Forms WordPress plugin has a critical flaw allowing anyone to upload dangerous files, potentially letting attackers take control of your website. This is a serious risk for any site using this plugin.

CVE advisoryCRITICAL

CVE-2026-47311

Samsung Escargot Heap Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in Samsung Escargot allows attackers to overflow buffers. This can impact systems and data, presenting a business risk. Attackers could gain unauthorized access or disrupt services. Organizations should identify affected assets and reduce exposure.

CVE advisoryCRITICAL

CVE-2026-47310

Escargot Pointer Manipulation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability in Samsung's Escargot component could permit pointer manipulation, potentially affecting system integrity and data availability. This presents a business risk due to possible data compromise and service disruption. Organizations using this component should address the vulnerability to mit