NVD disclosure day

Published threat advisories for May 20, 2026

CVE advisoryCRITICAL

CVE-2026-47372

Crypt::SaltedHash could allow external attacker to compromise user passwords.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Crypt::SaltedHash contains a flaw that allows an external attacker to predict the security codes protecting stored passwords. By cracking these passwords, attackers can gain unauthorized account access, potentially exposing sensitive customer data or compromising administrative systems.

CVE advisoryCRITICAL

CVE-2026-8631

HP Printing Software could allow internal attacker to gain unauthorized system control

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in HP Linux Imaging and Printing Software by sending malicious print files to gain elevated access. This allows the attacker to potentially take full administrative control over the impacted systems.

CVE advisoryCRITICAL

CVE-2026-9129

Altium Enterprise Server Viewer could allow internal attacker to steal secrets and gain access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a flaw in the Altium Enterprise Server Viewer to read unauthorized files on the system. This allows them to steal sensitive configuration data and credentials, creating a risk of full server compromise and data access.

CVE advisoryCRITICAL

CVE-2026-9102

Altium Enterprise Server allows attackers to take control of services and disrupt operations.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker can exploit a file upload weakness in Altium Enterprise Server to overwrite critical system files. This allows them to gain full control of the server, risking unauthorized access and major service disruption.

CVE advisoryKnown Exploit

CVE-2026-9082

Drupal websites could be taken over by attackers due to a critical flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in Drupal core allows unauthenticated attackers to inject malicious SQL commands, potentially leading to full system takeover and data theft. This vulnerability is actively exploited and requires immediate attention.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-20223

Attacker can gain admin control over Cisco Secure Workload by exploiting an access flaw

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can gain unauthorized administrative access to Cisco Secure Workload, allowing them to steal sensitive information and alter security configurations. This could result in a complete compromise of the organization's managed security environment.

CVE advisoryCRITICAL

CVE-2026-8467

Code injection in phoenix_storybook can let attackers run any code on your server.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit Phoenix Storybook to run malicious code on your server. This flaw could allow them to gain full administrative control, leading to unauthorized access to sensitive data and critical system infrastructure.

CVE advisoryKnown Exploit

CVE-2026-45498

Microsoft Defender Denial of Service Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A denial-of-service vulnerability exists in Microsoft Defender that could disrupt its security functions. While exploitation often requires local access, understanding this issue is important for confirming relevance and assessing potential exposure within your environment. The vulnerability affects the availability of

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-41091

Microsoft Defender could allow an internal attacker to gain higher system permissions

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with existing access could trick Microsoft Defender into granting them higher system permissions. This could allow the unauthorized user to gain full administrative control of the system, putting business data and security at risk.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-3593

BIND DNS-over-HTTPS Use-After-Free Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A use-after-free vulnerability in BIND 9's DNS-over-HTTPS implementation could allow an unauthenticated attacker to crash the service. This affects organizations using vulnerable versions of BIND 9, potentially leading to denial-of-service disruptions and impacting the availability of internet-facing DNS services. The

CVE advisoryCRITICAL

CVE-2025-31973

HCL BigFix Service Management vulnerability allows attackers to take control of your systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

HCL BigFix Service Management relies on outdated software components, which could allow an internal attacker to compromise the system. This could lead to a full administrative takeover of the platform and unauthorized access to sensitive configuration files.

CVE advisoryCRITICAL

CVE-2026-9059

NextGEN Gallery allows attackers with admin access to steal customer data or disrupt services.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with specific administrative permissions can manipulate NextGEN Gallery to extract or alter information. This vulnerability poses a risk to sensitive business data and could allow unauthorized control of the website.

CVE advisoryCRITICAL

CVE-2026-24207

Attackers can bypass security in NVIDIA Triton Inference Server to steal data or disrupt services.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An NVIDIA Triton Inference Server vulnerability allows attackers to bypass authentication and potentially execute code or steal data. This is critical because it impacts systems serving machine learning models, which are often deployed internally.

CVE advisoryCRITICAL

CVE-2026-24206

NVIDIA Triton Server has a flaw that lets attackers bypass security controls to steal data or disrupt service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The NVIDIA Triton Inference Server has an authentication flaw that an external attacker could exploit to bypass security controls. This could allow unauthorized access to sensitive model data, escalation of system privileges, or the disruption of critical machine learning operations.

CVE advisoryCRITICAL

CVE-2026-24163

NVIDIA TRT-LLM could allow an internal attacker to take control of systems or access data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The testing interface in NVIDIA TRT-LLM contains a security flaw that allows an internal attacker to execute unauthorized code or disrupt services. These actions could enable the compromise of the server and potential exposure of sensitive model information.

CVE advisoryCRITICAL

CVE-2026-24142

NVIDIA TensorRT-LLM allows attackers to take control, change data, or steal information.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can exploit a flaw in NVIDIA TRT-LLM to run unauthorized code, allowing them to steal sensitive data or gain full administrative control. This risk affects your core AI services and potentially compromises your entire business infrastructure.

CVE advisoryCRITICAL

CVE-2025-33255

NVIDIA TRT-LLM could allow an internal attacker to take control of systems and alter data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in NVIDIA TRT-LLM allows an internal attacker to gain unauthorized control of systems. This enables them to steal sensitive proprietary information, tamper with data, or crash services, directly threatening your model integrity and computing infrastructure.