NVD disclosure day

Published threat advisories for May 22, 2026

CVE advisoryHIGH

CVE-2026-25606

Authenticated users can access other people's data in STER

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with legitimate access can exploit search filters in STER to bypass security controls and retrieve private information belonging to other users. This exposes the business to potential widespread theft of sensitive organizational and customer data.

CVE advisoryMEDIUM

CVE-2026-8381

TeamViewer DEX Platform could allow internal attacker to gain administrative access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with low-level access can bypass security controls within the TeamViewer DEX Platform to run restricted commands. This allows them to take full control of the management software, risking unauthorized access to sensitive company data and critical IT infrastructure.

CVE advisoryMEDIUM

CVE-2026-7509

WordPress plugin lets attackers inject malicious code into your site affecting users.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker can inject malicious scripts into WordPress pages using the KIA Subtitle plugin, potentially hijacking user sessions or stealing credentials. This matters because it allows unauthorized script execution in users' browsers.

CVE advisoryCRITICAL

CVE-2026-9054

Attacker can crash 9front systems over the network

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can send malicious network traffic to the 9front operating system to trigger a total system crash. This vulnerability poses a significant risk to operations by allowing the attacker to cause repeated service outages, resulting in system downtime and a loss of user access.

CVE advisoryCRITICAL

CVE-2026-39831

Golang Crypto Library Vulnerability Allows Unattended Security Key Use.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a cryptographic library could allow signatures from security keys to be accepted without user presence. This could impact systems relying on these keys for authentication, potentially leading to unauthorized access. Organizations should identify affected systems and apply vendor-provided fixes.

CVE advisoryCRITICAL

CVE-2026-39830

Golang Crypto Library Vulnerability Leads to Resource Leak.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in the Go crypto library can disrupt SSH connections by filling an internal buffer with unsolicited responses, leading to resource leaks. Affected organizations may experience a degradation in service availability. Addressing this vulnerability is recommended to maintain system stability.

CVE advisoryHIGH

CVE-2026-34911

UniFi OS Path Traversal Leads to Sensitive Information Disclosure.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in UniFi OS devices could allow unauthorized access to system files, potentially exposing sensitive information. This risk matters to organizations because an attacker with low-level network access could exploit this flaw. The realistic business risk involves the compromise of confidential data.

CVE advisoryCRITICAL

CVE-2026-34910

UniFi OS flaw lets attackers on your network take full control and disrupt services

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker on your local network could exploit a flaw in UniFi OS devices to run unauthorized commands. This could allow them to gain full administrative control over your network hardware, potentially compromising your organization's entire network gateway.

CVE advisoryCRITICAL

CVE-2026-34909

UniFi OS devices can be accessed by an attacker to gain control of user accounts.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with network access could exploit a flaw in UniFi OS to read sensitive system files and gain administrative control over the device. This poses a risk to our network infrastructure by potentially exposing critical credentials and allowing unauthorized access to sensitive configurations.

CVE advisoryCRITICAL

CVE-2026-34908

UniFi OS devices could allow internal attacker to make unauthorized system changes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to your network can bypass security controls in UniFi OS devices to change system configurations without permission. This could allow them to alter firewall rules or user access, potentially giving them full control over your network and disrupting critical business services.

CVE advisoryCRITICAL

CVE-2026-33000

UniFi OS devices allow attackers with existing access to run commands and control your systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with high-level access to UniFi OS devices can misuse input features to run unauthorized commands. This could allow them to gain total control over critical network infrastructure and install persistent access.