NVD disclosure day

Published threat advisories for May 21, 2026

CVE advisoryHIGH

CVE-2026-8426

Concrete CMS Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Concrete CMS versions prior to 9.5.1 have a vulnerability that could allow an attacker to execute arbitrary code on the affected system. This occurs when an attacker manipulates a remote package update request. The potential impact includes unauthorized code execution on the web server, which could compromise data and

CVE advisoryHIGH

CVE-2026-8140

Concrete CMS Package Download Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Concrete CMS installations are affected by a vulnerability that allows an attacker to trick an authenticated administrator into downloading arbitrary marketplace packages, potentially leading to unauthorized software installation. The risk involves an unauthenticated attacker leveraging a CSRF flaw and an administrator

CVE advisoryHIGH

CVE-2026-8135

Concrete CMS Remote Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Concrete CMS versions prior to 9.5.1 could allow unauthorized code execution. An authenticated administrator could exploit this flaw via the REST API, potentially leading to complete server takeover. This poses a significant business risk to organizations using affected versions.

CVE advisoryMEDIUM

CVE-2026-4843

WordPress plugin lets low-access users delete Google Sheet data

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with basic website access can use the GSheet For Woo Importer plugin to delete API tokens and configuration settings. This unauthorized access disrupts product data synchronization, causing a loss of functionality in automated import and export workflows.

CVE advisoryHIGH

CVE-2026-47114

IINA Command Execution via Custom URL Scheme

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the IINA media player allows remote attackers to execute commands via a crafted URL. This could impact user systems by allowing arbitrary command execution upon user interaction with a malicious link and browser prompt. The business risk involves potential system compromise and unauthorized control.

CVE advisoryHIGH

CVE-2026-48248

Open ISES Tickets: TLS Certificate Verification Bypass in Login Process.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in Open ISES Tickets allows attackers to intercept sensitive data during login by bypassing security certificate checks. This impacts organizations using affected versions, risking exposure of API keys or session data. The realistic business risk involves potential data compromise during transit.

CVE advisoryHIGH

CVE-2026-48233

Open ISES Tickets SQL Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Open ISES Tickets allows authenticated attackers to access, modify, or delete database contents. This risk arises from unescaped input that can alter query logic, potentially compromising data integrity and confidentiality. Organizations using this software should address this to protect sensitive in

CVE advisoryHIGH

CVE-2026-9089

ConnectWise Automate Component Authenticity Risk.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

ConnectWise Automate™ Agent component authenticity may not be fully verified, potentially allowing unauthorized modifications. This could impact affected systems and data. Organizations should update to a version that addresses this vulnerability to mitigate business risk.

CVE advisoryHIGH

CVE-2026-45208

Apex One Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Trend Micro Apex One agents may allow a local attacker to gain elevated privileges. This requires the attacker to first execute low-privileged code on the system. The business risk includes unauthorized access to and modification of system data and operations.

CVE advisoryHIGH

CVE-2026-45207

Apex One Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Apex One/SEP agent allows local attackers with low-privileged code execution to escalate privileges. This impacts system confidentiality, integrity, and availability, posing a business risk. Exploitation requires prior access to the target system.

CVE advisoryHIGH

CVE-2026-45206

Apex One Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An origin validation vulnerability in the Apex One/SEP agent allows a local attacker with low-privileged code execution to escalate privileges. This impacts affected installations, potentially leading to data compromise and system compromise. Business risk is associated with unauthorized access and control over systems

CVE advisoryHIGH

CVE-2026-34929

Apex One Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability in Trend Micro Apex One allows a local attacker with low-privileged code execution to escalate privileges. Exploitation could lead to unauthorized access and disruption of business operations. The risk to organizations involves potential compromise of sensitive data and system control if the vulnerab

CVE advisoryHIGH

CVE-2026-34927

Apex One Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A local attacker with low-privileged code execution could escalate privileges on affected Trend Micro Apex One installations. This presents a business risk by potentially compromising protected systems, impacting data confidentiality, integrity, and availability. The risk is considered high due to the potential for pri

CVE advisoryKnown Exploit

CVE-2026-34926

Trend Micro Apex One could allow an internal attacker to deploy malicious code to devices.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with server administrative access can exploit Trend Micro Apex One (on-premise) to distribute harmful software to all connected computers. This is critical because it allows the attacker to gain persistent administrative control over all managed company devices.

• CISA KEV

CVE advisoryHIGH

CVE-2025-71216

Trend Micro Apex One Local Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A local attacker with low-privileged code execution could escalate privileges on Trend Micro Apex One (mac) agents. This impacts affected installations by potentially compromising system integrity and data confidentiality. The realistic business risk involves unauthorized access and control on compromised systems.

CVE advisoryHIGH

CVE-2025-71215

Trend Micro Apex One Agent Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Trend Micro Apex One allows a local attacker to escalate privileges. This could affect systems by enabling unauthorized access and control. The risk to organizations is associated with potential data compromise and system integrity if affected systems are not updated.

CVE advisoryHIGH

CVE-2025-71214

Trend Micro Apex One Local Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Trend Micro Apex One's iCore service may allow a local attacker with existing low-privileged access to escalate privileges, potentially impacting data and system control. This vulnerability requires an attacker to first gain limited code execution on the target system. Affected organizations should assess the

CVE advisoryCRITICAL

CVE-2025-71210

Trend Micro Apex One allows attackers to run commands on your systems if they can access the management console

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Trend Micro Apex One has a security flaw in its management console that allows an external attacker to upload and execute malicious files. This could grant an attacker full administrative control over your security infrastructure, allowing them to disable endpoint defenses and compromise the network.

CVE advisoryHIGH

CVE-2026-45255

FreeBSD Installation Tools Vulnerable to Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in FreeBSD's installation and configuration tools allows for code execution as root if a user initiates a Wi-Fi scan. An attacker within radio range could exploit this by creating a rogue access point with a specially crafted name, potentially impacting system integrity and data.

CVE advisoryHIGH

CVE-2026-45253

FreeBSD Kernel Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in FreeBSD's kernel ptrace functionality allows local users to escalate privileges, potentially gaining full system control. This impacts organizations by exposing systems to unauthorized access and data compromise. The realistic business risk involves loss of system integrity and confidentiality.

CVE advisoryHIGH

CVE-2026-45251

FreeBSD Local Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in the operating system can be exploited by a local user to gain elevated privileges. This risk is internal, requiring local access to trigger the vulnerability. Organizations should identify affected assets and apply necessary fixes.

CVE advisoryHIGH

CVE-2026-39461

FreeBSD Casper Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in FreeBSD's libcasper library could allow local privilege escalation. An attacker could trigger stack corruption by opening many file descriptors, potentially gaining elevated access if the affected application runs as root. This risk is associated with local access to the system.

CVE advisoryUNKNOWN

CVE-2026-5433

Honeywell Control Network Module allows an attacker to take control of industrial systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

By targeting the web interface of the Honeywell Control Network Module, an external attacker can gain full administrative control of the system. This risk could enable them to disrupt critical industrial operations or access broader internal networks.

CVE advisoryCRITICAL

CVE-2026-44050

Netatalk could allow an internal attacker to gain system control or disrupt services.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Netatalk has a security flaw that allows an internal attacker with valid credentials to gain full control of the system or crash the service. This could lead to unauthorized access to sensitive files and persistent system compromise, putting business data and operations at risk.

CVE advisoryCRITICAL

CVE-2026-9152

Altium 365 Search Index Unauthorized Access Advisory

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Altium 365's SearchService allows unauthenticated network access to search index operations. This could expose sensitive workspace information and compromise search result integrity. The risk to affected organizations includes data disclosure and manipulation of search results, impacting business ope