NVD disclosure day

Published threat advisories for May 26, 2026

CVE advisoryCRITICAL

CVE-2026-44668

Faction Unauthenticated Template Management Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can exploit a vulnerability in a penetration testing report generation framework to read, modify, or delete any system template. This issue arises from improper session validation before executing critical functions, potentially impacting system integrity and data availability when the appli

CVE advisoryCRITICAL

CVE-2026-48687

FastNetMon Juniper Plugin OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An OS command injection vulnerability exists in the Juniper router integration plugin for FastNetMon, where unsanitized input within a logging function can allow arbitrary command execution. This could lead to unauthorized system access or control if the plugin is reachable and invoked with malicious arguments. You sho

CVE advisoryCRITICAL

CVE-2026-4480

Samba 'print command' Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the Samba printing subsystem allows a remote attacker to execute code by sending a crafted print job. This occurs because the system does not properly escape shell meta-characters in the job description passed to the print command. This could lead to remote code execution on affected systems.

CVE advisoryKnown Exploit

CVE-2026-45247

Mirasvit Cache Warmer PHP Object Injection Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A PHP object injection vulnerability exists in Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated attackers to execute arbitrary code remotely by sending a crafted serialized PHP object in a cookie. This exploit leverages unrestricted calls to PHP's `unserialize()` function, potentially leading to

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-7374

KubeVirt virt-handler Symlink Validation Flaw Allows Node and Cluster Compromise.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in KubeVirt's virt-handler component allows an authenticated user with edit permissions to hijack privileged connections by exploiting improper symlink validation. This could lead to full control of the host node and the entire cluster.

CVE advisoryCRITICAL

CVE-2026-42496

Archive Tar Symlink Target Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Archive::Tar for Perl allows crafted archives with symbolic links to target arbitrary file paths outside the extraction directory, potentially enabling unauthorized file access or modification. This issue requires confirmation of usage and exposure within affected applications to assess its relevance