NVD disclosure day

Published threat advisories for May 28, 2026

CVE advisoryCRITICAL

CVE-2026-44848

Portainer Community Edition: Unauthorized Plugin Operations via Docker Daemon Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Portainer Community Edition allows standard users with Docker endpoint access to execute privileged plugin operations. This could enable unauthorized control over containerized environments, posing a significant business risk. Organizations should identify affected instances, restrict user access, an

CVE advisoryCRITICAL

CVE-2026-46840

Oracle REST Data Services Unauthenticated Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle REST Data Services allows unauthenticated attackers with network access to take over the service, potentially impacting other products. This issue is easily exploitable and has severe consequences for confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46839

Oracle REST Data Services Compromise Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle REST Data Services, a service that connects web browsers to Oracle databases, which could allow a low-privileged attacker with network access to completely compromise the service and potentially affect other products. This could impact confidentiality, integrity, and availabili

CVE advisoryCRITICAL

CVE-2026-46833

Oracle Database Server Net Service Vulnerability: Remote Takeover Risk.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Database Server's Net Service component allows an unauthenticated attacker with network access to compromise the service, potentially leading to a takeover. This impacts confidentiality, integrity, and availability, posing a significant business risk. Exploitation is difficult but can affect a

CVE advisoryCRITICAL

CVE-2026-46817

Oracle E-Business Suite File Transmission Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Payments within Oracle E-Business Suite's File Transmission component, allowing unauthenticated attackers with network access to achieve a complete takeover of the system. This could impact data confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46775

Oracle REST Data Services Vulnerability Allows System Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle REST Data Services allows a low-privileged attacker with network access to take over the service. This could significantly impact other connected products and pose a risk to data confidentiality, integrity, and availability. Organizations should identify affected assets and apply vendor fixes.

CVE advisoryCRITICAL

CVE-2026-45374

CodeWhale Agents May Allow Unauthorized Shell Access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in CodeWhale's task creation tool may permit sub-agents unrestricted shell access when a user approves a task. This could allow attackers to gain unauthorized control over affected systems, potentially leading to data compromise and significant business risk. Organizations should review their use of this tool.

CVE advisoryCRITICAL

CVE-2026-45323

MeshCore Card Allows Arbitrary JavaScript Execution in Home Assistant.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The MeshCore Lovelace card for Home Assistant is affected by a vulnerability that allows for arbitrary JavaScript execution. This could impact internal systems by enabling unauthorized actions or data exposure within the Home Assistant frontend. The realistic business risk involves potential compromise of sensitive dat

CVE advisoryCRITICAL

CVE-2026-45311

CodeWhale Allows Arbitrary Code Execution From Malicious Repositories.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in a coding agent allows malicious code execution from unapproved repositories, potentially leading to credential theft or system compromise. The risk stems from automatic test execution without user consent, impacting organizational security and data integrity.

CVE advisoryCRITICAL

CVE-2026-44477

CloudNativePG Metrics Exporter Privilege Escalation Risk.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the CloudNativePG metrics exporter allows an attacker with limited privileges to execute OS commands as the `postgres` user. This can impact affected organizations by enabling unauthorized access to sensitive data and compromising database systems and infrastructure. The risk to business operations i

CVE advisoryCRITICAL

CVE-2026-4408

Samba File Server Remote Command Execution Advisory

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A misconfiguration in Samba file servers can allow remote command execution by attackers exploiting the "check password script" feature with specific substitution characters. This affects non-standard configurations and presents a business risk of unauthorized system control.