NVD disclosure day

Published threat advisories for May 27, 2026

CVE advisoryKnown Exploit

CVE-2026-48027

Nx Console Compromise Allows Unauthorized Access to Sensitive Data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A malicious version of Nx Console was briefly available, containing code that could harvest credentials. Organizations using the affected version could experience unauthorized access to sensitive information. Upgrading to a non-compromised version mitigates this risk.

• CISA KEV

CVE advisoryHIGH

CVE-2025-70103

Libjxl Component Image Processing Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap buffer overflow vulnerability in the libjxl library could permit attackers to access or alter data by providing specially crafted PBM images. This poses a business risk to organizations relying on the library for image processing, potentially leading to service disruption or data compromise.

CVE advisoryCRITICAL

CVE-2026-8175

IBM Aspera httpd Buffer Overflow Denial of Service and Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A buffer overflow vulnerability in IBM Aspera's network transfer component could allow unauthenticated attackers to cause denial of service, bypass authentication, or execute remote code, impacting service availability and integrity.

CVE advisoryCRITICAL

CVE-2026-7876

IBM Aspera HSTS Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Aspera HSTS for CP4I is affected by an authentication bypass vulnerability that may allow unauthorized access to files. If reachable, this could expose sensitive data within the server's local storage when certain restrictions are absent. The concern lies in confirming the relevance and exposure of this technology

CVE advisoryCRITICAL

CVE-2026-7524

IBM Langflow OSS Archive Extraction Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS versions 1.0.0 through 1.9.1 have a remote code execution flaw due to improper symbolic link validation during archive extraction. This could allow an attacker to execute unauthorized code on affected systems, creating a significant business risk.

CVE advisoryCRITICAL

CVE-2026-46043

Linux Kernel RDMA Vulnerability Allows Packet Underflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA component could allow specially crafted network packets to cause an integer underflow, potentially leading to system instability or unauthorized data access. This issue stems from insufficient validation of packet lengths and padding during data reception.

CVE advisoryCRITICAL

CVE-2026-46039

Linux Kernel rxgk Integer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A Linux kernel vulnerability has been fixed that could lead to an integer overflow during a length check, potentially impacting system integrity and availability. The issue involves the `rxgk` component's handling of ticket lengths. It is uncertain if this internal function is reachable or relevant in your specific env

CVE advisoryCRITICAL

CVE-2026-45988

Linux Kernel rxrpc Packet Re-decryption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Linux kernel's rxrpc protocol that could allow response packets to be re-decrypted incorrectly, potentially leading to data exposure or integrity issues. While not typically internet-facing, the protocol's network nature means that if reachable, this flaw could impact system confidentialit

CVE advisoryCRITICAL

CVE-2026-45972

Linux Kernel SMB Client UAF and Double Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the Linux kernel's SMB client can lead to memory corruption, potentially causing instability or compromise. This vulnerability is relevant if the SMB client functionality is exposed or used in your environment. The issue is resolved in newer kernel versions.

CVE advisoryCRITICAL

CVE-2026-45898

Linux Kernel RDMA Workqueue Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Linux kernel vulnerability in the RDMA/iWARP component can cause workqueue list corruption due to improper handling of submitted work items. This issue could potentially lead to system instability or crashes if triggered. The affected technology is part of the kernel's internal task management.

CVE advisoryCRITICAL

CVE-2025-12686

Synology BeeStation OS Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability in Synology BeeStation OS allows remote attackers to execute arbitrary code. This could lead to unauthorized access and potential data compromise for affected organizations. The realistic business risk involves a breach of system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-9312

GitHub Enterprise Server: Unauthenticated Access to Internal Services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in GitHub Enterprise Server allows unauthenticated attackers to access internal services and potentially sensitive credentials. The issue stems from insufficient input validation in an upload endpoint, enabling attackers to redirect internal API calls. This presents a busines