NVD disclosure day

Published threat advisories for May 25, 2026

CVE advisoryCRITICAL

CVE-2026-42774

JetEngine SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL Injection vulnerability exists in the JetEngine component, potentially allowing attackers to access or manipulate database information. The impact depends on whether JetEngine is used, as exploitation requires network reachability. Confirmation of its presence and assessment of data exposure are necessar

CVE advisoryCRITICAL

CVE-2026-42773

eMagicOne Store Manager Blind SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Blind SQL Injection vulnerability in eMagicOne Store Manager may permit attackers to execute arbitrary SQL commands, potentially exposing sensitive system data. This issue, stemming from improper neutralization of SQL commands, is relevant if the software is in use and reachable by attackers, necessitating verificati

CVE advisoryCRITICAL

CVE-2026-9058

Szafir SDK Signature Verification Flaw Allows Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Szafir SDK incorrectly validates digital signatures when a signer's certificate cannot be trusted, potentially allowing authentication bypass and user impersonation. This vulnerability enables applications using the SDK to accept invalid signatures as legitimate. It is uncertain if or where the Szafir SDK is implem

CVE advisoryCRITICAL

CVE-2026-2651

MLflow Artifact Uploads Allow Unauthorized Cross-User Writes

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in MLflow allows unauthorized users to overwrite artifacts when artifact serving is enabled, potentially leading to model supply chain poisoning and arbitrary code execution. The authorization logic lacks resource-level permission checks for certain endpoints, enabling cross-user writes.