NVD disclosure day

Published threat advisories for May 27, 2026

CVE advisoryKnown Exploit

CVE-2026-48027

Nx Console Compromise Allows Unauthorized Access to Sensitive Data.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A malicious version of Nx Console was briefly available, containing code that could harvest credentials. Organizations using the affected version could experience unauthorized access to sensitive information. Upgrading to a non-compromised version mitigates this risk.

• CISA KEV

CVE advisoryHIGH

CVE-2025-70103

Libjxl Component Image Processing Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap buffer overflow vulnerability in the libjxl library could permit attackers to access or alter data by providing specially crafted PBM images. This poses a business risk to organizations relying on the library for image processing, potentially leading to service disruption or data compromise.

CVE advisoryCRITICAL

CVE-2025-12686

Synology BeeStation OS Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability in Synology BeeStation OS allows remote attackers to execute arbitrary code. This could lead to unauthorized access and potential data compromise for affected organizations. The realistic business risk involves a breach of system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-9312

GitHub Enterprise Server: Unauthenticated Access to Internal Services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in GitHub Enterprise Server allows unauthenticated attackers to access internal services and potentially sensitive credentials. The issue stems from insufficient input validation in an upload endpoint, enabling attackers to redirect internal API calls. This presents a busines