NVD disclosure day

Published threat advisories for May 22, 2026

CVE advisoryKnown Exploit

CVE-2026-45659

Microsoft SharePoint Server Code Execution via Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Microsoft SharePoint Server allows an authorized attacker to execute code over a network by deserializing untrusted data. This could permit an attacker to compromise the affected system. The issue is considered externally exposed, meaning it is likely reachable via the internet.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-39821

golang net ToUnicode Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The `golang/net` package's `idna` library has a vulnerability where Punycode-encoded domain names can be accepted as valid ASCII hostnames, potentially leading to privilege escalation. This occurs when programs check hostnames in ASCII format and then convert them to Unicode. The relevance depends on applications proce

CVE advisoryCRITICAL

CVE-2026-9277

Shell-quote quote() Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the shell-quote library's `quote()` function could allow unintended command execution if input containing line terminators is processed. This occurs because newline characters are not properly escaped, leading to command separation and execution in POSIX shells. This could be relevant for application

CVE advisoryCRITICAL

CVE-2026-44930

Apache CXF LDAP Injection Allows Certificate Retrieval

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An LDAP injection vulnerability exists in Apache CXF's XKMS server, potentially allowing an attacker to retrieve arbitrary certificates. This could expose sensitive certificate information if the XKMS component is reachable. It is important to determine if this component is in use and assess its potential exposure.An L

CVE advisoryHIGH

CVE-2026-25606

Authenticated users can access other people's data in STER

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with legitimate access can exploit search filters in STER to bypass security controls and retrieve private information belonging to other users. This exposes the business to potential widespread theft of sensitive organizational and customer data.

CVE advisoryMEDIUM

CVE-2026-8381

TeamViewer DEX Platform could allow internal attacker to gain administrative access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with low-level access can bypass security controls within the TeamViewer DEX Platform to run restricted commands. This allows them to take full control of the management software, risking unauthorized access to sensitive company data and critical IT infrastructure.

CVE advisoryMEDIUM

CVE-2026-7509

WordPress plugin lets attackers inject malicious code into your site affecting users.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker can inject malicious scripts into WordPress pages using the KIA Subtitle plugin, potentially hijacking user sessions or stealing credentials. This matters because it allows unauthorized script execution in users' browsers.

CVE advisoryCRITICAL

CVE-2026-9054

Attacker can crash 9front systems over the network

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker can send malicious network traffic to the 9front operating system to trigger a total system crash. This vulnerability poses a significant risk to operations by allowing the attacker to cause repeated service outages, resulting in system downtime and a loss of user access.

CVE advisoryCRITICAL

CVE-2026-46595

Golang Crypto SSH Authorization Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical authorization bypass vulnerability exists in the golang crypto library's SSH server configurations. If specific callback types are used, source-address validation can be skipped, potentially allowing unauthorized access. The risk depends on how applications implement and expose this library.

CVE advisoryCRITICAL

CVE-2026-39832

OpenSSH Remote Agent Key Restriction Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a cryptographic library allows destination restrictions on remote agent keys to be bypassed, potentially enabling unrestricted use of a key on a remote host. This could allow unauthorized actions if applications using the library are reachable. Confirmation of affected applications and their critical

CVE advisoryCRITICAL

CVE-2026-39831

Golang Crypto Library Vulnerability Allows Unattended Security Key Use.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a cryptographic library could allow signatures from security keys to be accepted without user presence. This could impact systems relying on these keys for authentication, potentially leading to unauthorized access. Organizations should identify affected systems and apply vendor-provided fixes.

CVE advisoryCRITICAL

CVE-2026-39830

Golang Crypto Library Vulnerability Leads to Resource Leak.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in the Go crypto library can disrupt SSH connections by filling an internal buffer with unsolicited responses, leading to resource leaks. Affected organizations may experience a degradation in service availability. Addressing this vulnerability is recommended to maintain system stability.

CVE advisoryHIGH

CVE-2026-34911

UniFi OS Path Traversal Leads to Sensitive Information Disclosure.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in UniFi OS devices could allow unauthorized access to system files, potentially exposing sensitive information. This risk matters to organizations because an attacker with low-level network access could exploit this flaw. The realistic business risk involves the compromise of confidential data.

CVE advisoryKnown Exploit

CVE-2026-34910

UniFi OS flaw lets attackers on your network take full control and disrupt services

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker on your local network could exploit a flaw in UniFi OS devices to run unauthorized commands. This could allow them to gain full administrative control over your network hardware, potentially compromising your organization's entire network gateway.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-34909

UniFi OS devices can be accessed by an attacker to gain control of user accounts.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with network access could exploit a flaw in UniFi OS to read sensitive system files and gain administrative control over the device. This poses a risk to our network infrastructure by potentially exposing critical credentials and allowing unauthorized access to sensitive configurations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-34908

UniFi OS devices could allow internal attacker to make unauthorized system changes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker with access to your network can bypass security controls in UniFi OS devices to change system configurations without permission. This could allow them to alter firewall rules or user access, potentially giving them full control over your network and disrupting critical business services.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-33000

UniFi OS devices allow attackers with existing access to run commands and control your systems.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An internal attacker with high-level access to UniFi OS devices can misuse input features to run unauthorized commands. This could allow them to gain total control over critical network infrastructure and install persistent access.