NVD disclosure day

Published threat advisories for May 29, 2026

CVE advisoryCRITICAL

CVE-2026-44649

SillyTavern: Unauthorized User Authentication Risk.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in SillyTavern's single sign-on configuration could allow unauthorized users to impersonate any user, including administrators, without a password. This affects organizations using specific, optional SSO features. The business risk involves potential unauthorized access and control of the application.

CVE advisoryCRITICAL

CVE-2026-7786

USR-W610 Firmware Exposes Plaintext Administrative Credentials

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Plaintext administrative credentials embedded in the firmware of Jinan USR IOT Technology Limited USR-W610 converters can be extracted through firmware analysis. This could allow unauthorized authentication to device services, potentially exposing connected industrial or IoT equipment.

CVE advisoryCRITICAL

CVE-2026-5386

KMW CCTV Security Cameras Unauthenticated Password Reset Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

KMW CCTV Security Cameras have a critical vulnerability allowing unauthenticated remote password resets. This could grant attackers full access to camera feeds and settings, compromising monitored areas. Confirm device exposure and relevance to assess risk.

CVE advisoryCRITICAL

CVE-2026-45661

Dokploy Path Traversal Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy allows authenticated users to write arbitrary files to remote servers, leading to code execution and potential server compromise. This impacts organizations by risking data exfiltration and persistent backdoor installations. The business risk involves unauthorized access and operational disru

CVE advisoryCRITICAL

CVE-2026-45632

Dokploy Organization Checks Bypass Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy contains a flaw where its schedule router fails to enforce organization and role checks, allowing authenticated users to manipulate schedules outside their own organization. This can lead to unauthorized script execution on servers, enabling remote code execution and posing a significant business risk.

CVE advisoryCRITICAL

CVE-2026-45625

Arcane GitOps Credential Exfiltration Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Arcane, an interface for managing Docker containers, has a critical vulnerability where any logged-in user can exfiltrate plaintext Git credentials. This occurs by manipulating Git repository configurations to send credentials to an attacker-controlled host. This impacts code security and access controls.

CVE advisoryCRITICAL

CVE-2026-45663

Dokploy Command Injection Vulnerability Exposes Host System.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in Dokploy's file upload functionality allows authenticated users to execute arbitrary operating system commands on the host. This impacts affected organizations by posing risks to systems, data, and services. The realistic business risk includes unauthorized control over the host envi

CVE advisoryCRITICAL

CVE-2026-44962

Plesk APS Catalog XPath Injection Leading to OS Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Plesk's APS Application Catalog search contains an XPath injection flaw, enabling authenticated, low-privileged users to execute arbitrary OS commands, potentially leading to local privilege escalation. This is significant as Plesk is a widely used web hosting control panel.

CVE advisoryCRITICAL

CVE-2026-10042

Manga Image Translator Unsafe Pickle Deserialization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Manga Image Translator's shared API server mode has a vulnerability that permits remote code execution by deserializing untrusted pickle data through specific API endpoints. This could lead to arbitrary code execution and full container compromise if deployed in Docker as root. Readers should care because an unauthenti

CVE advisoryCRITICAL

CVE-2026-46376

FreePBX UCP Hardcoded Credentials Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

FreePBX, an IP PBX system, has a vulnerability allowing unauthenticated users to access the User Control Panel (UCP) if initial credentials were not changed. This could expose communication functionalities and sensitive data to unauthorized access, making it important for deployed and unpatched instances to be addresse

CVE advisoryCRITICAL

CVE-2026-8326

Remote Spark SparkView Path Traversal Vulnerability Allows RCE

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A path traversal vulnerability exists in Remote Spark's SparkView RDP drive redirection, potentially allowing unauthenticated attackers to read, write, and execute arbitrary files with root privileges. This could lead to remote code execution and compromise of affected systems.

CVE advisoryCRITICAL

CVE-2026-45043

RustFS Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in RustFS, a distributed object storage system, allows a user with specific privileges to escalate their access to full administrative control. This could impact organizations by enabling unauthorized access to and manipulation of stored data. The realistic business risk involves potential data breaches

CVE advisoryCRITICAL

CVE-2026-10071

DreamMaker Arbitrary File Upload Leads to Server Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An Arbitrary File Upload vulnerability in DreamMaker software enables unauthenticated remote attackers to upload and execute malicious files, potentially leading to arbitrary code execution on the server. This could impact server operations and integrity if the software is in use and exposed to potential threats.

CVE advisoryCRITICAL

CVE-2026-9559

Mautic Campaign Import Path Traversal Leads to Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in a marketing automation platform's campaign import feature allows an authenticated user to write arbitrary files to sensitive system directories. This could lead to overwriting critical system components and result in remote code execution.

CVE advisoryCRITICAL

CVE-2025-41276

Waterfall WF-500 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in the Console WebUI of Waterfall WF-500 network appliances, allowing unauthenticated remote attackers to execute arbitrary commands on the device. This could lead to a compromise of the network appliance, impacting its intended function.

CVE advisoryCRITICAL

CVE-2025-41275

Waterfall WF-500 OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Waterfall WF-500 devices have a critical OS command injection vulnerability in their Console WebUI, allowing unauthenticated remote attackers to execute arbitrary commands. This affects industrial security appliances, and its reachability is classified as external, posing a risk to device integrity and availability.

CVE advisoryCRITICAL

CVE-2025-41274

Waterfall WF-500 Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Remote, unauthenticated attackers can execute arbitrary OS commands on Waterfall WF-500 devices due to OS command injection in the Console WebUI. This vulnerability allows attackers to potentially gain control of the device, making it critical to identify if these network-accessible appliances are in use and assess the

CVE advisoryCRITICAL

CVE-2025-41273

Waterfall WF-500 Authentication Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Waterfall WF-500 hosts allows unauthenticated attackers to bypass authentication for the Console web application. This could enable them to perform actions as an authenticated user. The relevance depends on whether these devices are exposed in a manner that makes exploitation possible.

CVE advisoryCRITICAL

CVE-2025-41270

Waterfall WF-500 Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in the Console WebUI of Waterfall WF-500 devices, allowing unauthenticated remote attackers to execute arbitrary operating system commands. This could compromise the device's integrity and function, impacting the security of protected systems. The relevance and exposure

CVE advisoryCRITICAL

CVE-2026-9558

Mautic Theme Engine Server-Side Template Injection Leads to Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Server-Side Template Injection vulnerability in Mautic's theme engine allows authenticated users with theme upload permissions to execute arbitrary code on the hosting server or access sensitive system files. This occurs because uploaded Twig templates are rendered without proper security restrictions. Affected reade

CVE advisoryCRITICAL

CVE-2026-49201

Acer Wave 7 Firmware Backup Encryption Key Hardcoded Leading to Backdoor Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hardcoded encryption key in a device backup binary allows attackers to decrypt, modify, and re-encrypt backups, potentially injecting persistent backdoors. This impacts network devices and warrants review for relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-49200

Acer Wave 7 Firmware Unauthenticated Log Access Exposes Credentials.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability in Acer firmware allows access to a log file containing cleartext credentials via the web interface. This exposure could lead to unauthorized system access. Readers should care because sensitive login information may be compromised without proper authentication.An unauthenticated vulner

CVE advisoryCRITICAL

CVE-2026-49199

Acer Predator Connect W6x Firmware Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in network-connected devices allows for root-level command injection through crafted network messages. This could enable unauthorized code execution and complete device compromise if reachable over a network. Understanding the reachability and criticality of affected devices is essential.

CVE advisoryCRITICAL

CVE-2026-49197

Acer Predator Connect Authorization Header Validation Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Web endpoints for Acer Connect firmware improperly validate HTTP Authorization headers, allowing unauthenticated requests when Base64 decoding fails. This could lead to unauthorized access and compromise of confidentiality, integrity, and availability, impacting network-connected devices.

CVE advisoryCRITICAL

CVE-2026-3655

OTP Login With Phone Number Plugin Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authentication bypass vulnerability exists in the OTP Login With Phone Number, OTP Verification WordPress plugin. This flaw allows unauthenticated attackers to impersonate any user, including administrators, by manipulating the Firebase verification process. The vulnerability occurs when the plugin fails to

CVE advisoryCRITICAL

CVE-2026-8732

WP Maps Pro Administrator Account Creation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the WP Maps Pro WordPress plugin allows unauthenticated attackers to create new administrator accounts, potentially leading to a full website takeover. The flaw, present in all versions up to 6.1.0, involves an improperly secured AJAX action that bypasses normal security checks. Attackers ca