NVD disclosure day

Published threat advisories for May 28, 2026

CVE advisoryCRITICAL

CVE-2026-9918

Chrome Tint Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's Tint component may allow a remote attacker to escape the browser sandbox via a crafted HTML page. Exploitation could potentially lead to broader system compromise if a user visits a malicious webpage. The primary concern is confirming the relevance and exposure of this vulnerability w

CVE advisoryCRITICAL

CVE-2026-9891

Chrome Extension Use After Free Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome extensions allows a sandbox escape. This requires an attacker to first compromise the renderer process and then use a crafted extension. This could lead to broader system access on supported operating systems.

CVE advisoryCRITICAL

CVE-2026-9874

Chrome Sandbox Escape via Use After Free in Dawn

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome allows remote attackers to potentially escape the browser sandbox via a crafted HTML page. This could lead to a compromise of the user's system. The specific impact and necessary actions depend on the reachability of affected users and installations.

CVE advisoryCRITICAL

CVE-2026-8809

Advanced Custom Fields Extended Privilege Escalation via Validation Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A validation bypass in the Advanced Custom Fields: Extended WordPress plugin allows unauthenticated attackers to create new administrator accounts. This occurs when a public frontend form is configured with a Create User action, enabling attackers to bypass role validation checks. The vulnerability's reachability depen

CVE advisoryCRITICAL

CVE-2026-44849

Portainer Community Edition Swarm API Security Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Portainer Community Edition allows authenticated users to bypass security restrictions when configuring Docker Swarm services, potentially leading to unintended access or actions. This issue affects specific versions of the container management platform and could allow non-administrative users to lau

CVE advisoryCRITICAL

CVE-2026-44848

Portainer Community Edition: Unauthorized Plugin Operations via Docker Daemon Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Portainer Community Edition allows standard users with Docker endpoint access to execute privileged plugin operations. This could enable unauthorized control over containerized environments, posing a significant business risk. Organizations should identify affected instances, restrict user access, an

CVE advisoryCRITICAL

CVE-2026-9645

Authenticated Code Execution Leading to Root Compromise

Halo Surface Signal: 3 out of 5 — possibly public-facing.

This vulnerability allows authenticated users to create and execute arbitrary JavaScript code on the server with root privileges, potentially leading to complete system compromise. While authenticated access is required, the direct execution of commands as root necessitates careful review of affected systems and their

CVE advisoryCRITICAL

CVE-2026-46840

Oracle REST Data Services Unauthenticated Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle REST Data Services allows unauthenticated attackers with network access to take over the service, potentially impacting other products. This issue is easily exploitable and has severe consequences for confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46839

Oracle REST Data Services Compromise Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle REST Data Services, a service that connects web browsers to Oracle databases, which could allow a low-privileged attacker with network access to completely compromise the service and potentially affect other products. This could impact confidentiality, integrity, and availabili

CVE advisoryCRITICAL

CVE-2026-46833

Oracle Database Server Net Service Vulnerability: Remote Takeover Risk.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Database Server's Net Service component allows an unauthenticated attacker with network access to compromise the service, potentially leading to a takeover. This impacts confidentiality, integrity, and availability, posing a significant business risk. Exploitation is difficult but can affect a

CVE advisoryCRITICAL

CVE-2026-46824

Oracle Universal Work Queue Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Universal Work Queue, part of Oracle E-Business Suite, allows low-privileged attackers with network access to potentially take over the system. Successful exploitation could impact additional products, leading to significant consequences. This issue affects supported versions and is a

CVE advisoryCRITICAL

CVE-2026-46822

Oracle iAssets Internal Operations Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle iAssets, a component of Oracle E-Business Suite. Attackers with network access and low privileges can exploit this to take over the iAssets system, potentially impacting other connected products. Confirmation of affected instances and their network exposure is recommended.

CVE advisoryKnown Exploit

CVE-2026-46817

Oracle E-Business Suite File Transmission Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Payments within Oracle E-Business Suite's File Transmission component, allowing unauthenticated attackers with network access to achieve a complete takeover of the system. This could impact data confidentiality, integrity, and availability.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-46775

Oracle REST Data Services Vulnerability Allows System Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle REST Data Services allows a low-privileged attacker with network access to take over the service. This could significantly impact other connected products and pose a risk to data confidentiality, integrity, and availability. Organizations should identify affected assets and apply vendor fixes.

CVE advisoryCRITICAL

CVE-2026-45288

Marten SQL Injection Vulnerability in Full-Text Search APIs.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Marten database library is vulnerable to SQL injection through its full-text search APIs when processing untrusted input, potentially allowing attackers to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or deletion of sensitive data, depending on how the application implements

CVE advisoryCRITICAL

CVE-2026-45374

CodeWhale Agents May Allow Unauthorized Shell Access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in CodeWhale's task creation tool may permit sub-agents unrestricted shell access when a user approves a task. This could allow attackers to gain unauthorized control over affected systems, potentially leading to data compromise and significant business risk. Organizations should review their use of this tool.

CVE advisoryCRITICAL

CVE-2026-45323

MeshCore Card Allows Arbitrary JavaScript Execution in Home Assistant.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The MeshCore Lovelace card for Home Assistant is affected by a vulnerability that allows for arbitrary JavaScript execution. This could impact internal systems by enabling unauthorized actions or data exposure within the Home Assistant frontend. The realistic business risk involves potential compromise of sensitive dat

CVE advisoryCRITICAL

CVE-2026-45311

CodeWhale Allows Arbitrary Code Execution From Malicious Repositories.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in a coding agent allows malicious code execution from unapproved repositories, potentially leading to credential theft or system compromise. The risk stems from automatic test execution without user consent, impacting organizational security and data integrity.

CVE advisoryCRITICAL

CVE-2026-44477

CloudNativePG Metrics Exporter Privilege Escalation Risk.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the CloudNativePG metrics exporter allows an attacker with limited privileges to execute OS commands as the `postgres` user. This can impact affected organizations by enabling unauthorized access to sensitive data and compromising database systems and infrastructure. The risk to business operations i

CVE advisoryCRITICAL

CVE-2026-46195

Linux Kernel SMB Client DACL Pointer Validation Flaw.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client could allow a malicious server to overwrite memory, potentially leading to system compromise. This occurs when a Linux system connects to a compromised SMB server, which then sends malformed data to exploit a flaw in how the kernel handles security descriptor offsets. Wh

CVE advisoryCRITICAL

CVE-2026-46155

Linux Kernel SMB Client Out-of-Bounds Read Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's SMB client allows an attacker to read adjacent kernel heap memory. This occurs when a specially crafted, truncated server response triggers an out-of-bounds read during data copying. The issue could lead to information disclosure from kernel memory if reachable.

CVE advisoryCRITICAL

CVE-2026-46119

Linux Kernel libceph Out-of-Bounds Access in Auth Reply Processing.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's `libceph` component allows for an out-of-bounds memory access during authentication reply processing. If a system receives a crafted authentication message with an invalid result value, it could expose sensitive memory contents. This impacts the integrity of system memory and requi

CVE advisoryCRITICAL

CVE-2026-46115

Linux Kernel BIOvec Merge Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel allows for the improper merging of physically contiguous memory segments that belong to different device pagemaps. This could lead to the kernel being unable to recover the correct pagemap for the merged segment, potentially impacting system integrity. The issue is related to interna

CVE advisoryCRITICAL

CVE-2026-4408

Samba File Server Remote Command Execution Advisory

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A misconfiguration in Samba file servers can allow remote command execution by attackers exploiting the "check password script" feature with specific substitution characters. This affects non-standard configurations and presents a business risk of unauthorized system control.