NVD disclosure day

Published threat advisories for June 1, 2026

CVE advisoryCRITICAL

CVE-2026-25879

Langroid SQL Injection Leading to Database Host RCE.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Langroid's SQLChatAgent allows attackers to execute arbitrary commands on a database host if the agent is configured with over-privileged database roles and an attacker can influence its input. This could lead to significant compromise of the database server. Uncertainty exists regarding exploitabili

CVE advisoryCRITICAL

CVE-2026-40965

Cloud Foundry UAA EC Private Key Exposure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in Cloud Foundry UAA that may expose EC private keys through the public `/token_keys` endpoint. This could allow attackers to forge tokens or impersonate users and services. It is uncertain if this vulnerability has been exploited or what specific business impact could occur.

CVE advisoryKnown Exploit

CVE-2025-48595

Android Integer Overflow Code Execution and Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability in the Android operating system may allow for code execution and local privilege escalation without user interaction. This could impact system data and service behavior. This issue is classified as internal due to its local attack vector.

• CISA KEV

CVE advisoryCRITICAL

CVE-2018-25427

Arm Whois Stack Buffer Overflow Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stack-based buffer overflow in Arm Whois allows remote attackers to execute arbitrary code by providing oversized input to the IP address or domain field, which can overwrite program structures and lead to command execution. The relevance and exposure of this vulnerability within our environment need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-9319

IBM WebSphere Application Server Deserialization Vulnerability via JAX-WS WS-Security

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM WebSphere Application Server is affected by a deserialization vulnerability through JAX-WS endpoints with WS-Security. If reachable, an attacker could potentially execute arbitrary code remotely. This is relevant for systems using the affected software, as it could impact system integrity and data confidentiality.

CVE advisoryCRITICAL

CVE-2026-9311

IBM WebSphere Application Server Security Bypass Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM WebSphere Application Server has a security bypass vulnerability that could permit remote code execution. This critical flaw impacts a widely deployed enterprise middleware platform, often used in internet-facing capacities, making it important to assess our exposure to this risk. The vulnerability allows attackers

CVE advisoryCRITICAL

CVE-2026-49121

AI Tensor Engine ROCm MessageQueue Pickle Deserialization RCE

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in AI Tensor Engine for ROCm allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a MessageQueue.recv() function. This could result in unauthorized commands being run on remote reader workers within a cluster network if attackers can reach the XPUB e

CVE advisoryCRITICAL

CVE-2026-0072

Android InputMethodManagerService Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Android's InputMethodManagerService, a core system component, allows for local privilege escalation without requiring user interaction or special access. While no specific sensitive data is indicated as at risk, this flaw could impact system integrity. Confirmation of relevance and exposure is needed

CVE advisoryCRITICAL

CVE-2026-45132

CloudPirates Helm Charts Workflow Exposes Sensitive Credentials

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in CloudPirates Open Source Helm Charts' GitHub Actions workflow could expose sensitive credentials, like Personal Access Tokens and SSH signing keys, due to unsafe handling of forked code. While patched, this exposure in a development pipeline warrants attention to confirm relevance and potent

CVE advisoryCRITICAL

CVE-2026-45131

CloudPirates Helm Charts GitHub Actions Workflow Exposes Secrets

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in CloudPirates Open Source Helm Charts' GitHub Actions workflow could allow attacker-controlled code from fork pull requests to execute in a privileged context, potentially exposing sensitive repository secrets without maintainer approval. This could impact the confidentiality of stored credentials and

CVE advisoryCRITICAL

CVE-2026-44211

Cline Cross-Origin WebSocket Hijack Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A cross-origin WebSocket hijack vulnerability exists in Cline Kanban servers, potentially allowing unauthorized access and control if a user interacts with a malicious website. The exact impact and affected data are uncertain, but the critical severity warrants understanding Cline's presence and use within the organiza

CVE advisoryCRITICAL

CVE-2026-42672

WP Directory Kit Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in WP Directory Kit could allow attackers to manipulate database queries, potentially leading to unauthorized access to sensitive information. This issue affects publicly accessible websites using the plugin, making it reachable over the network. Readers should verify the plugin's

CVE advisoryCRITICAL

CVE-2026-8931

Disig Web Signer Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in Disig Web Signer, a web-based digital signing tool. If reachable, attackers could potentially execute arbitrary code on user systems by tricking them into interacting with malicious content. This warrants confirmation of its use and assessment of potential exposu

CVE advisoryCRITICAL

CVE-2026-42682

wpForo Forum Missing Authorization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the wpForo Forum plugin could allow unauthenticated attackers to bypass access controls, potentially leading to unauthorized modifications of forum data or service disruption. It is uncertain if this plugin is in use within your organization, but confirmation is recommended to understand pot

CVE advisoryCRITICAL

CVE-2026-42680

Contest Gallery Pro Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect privilege assignment vulnerability exists in the Contest Gallery Pro plugin, potentially allowing privilege escalation. If reachable, this could permit unauthorized users to gain elevated privileges, posing a significant risk to system data and settings. Confirming the use and exposure of this plugin is cr

CVE advisoryCRITICAL

CVE-2026-0826

Poly Voice ICE Buffer Overflow Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical buffer overflow vulnerability exists in Poly Voice products on Linux when Interactive Connectivity Establishment (ICE) is enabled, potentially allowing remote code execution. If reachable, an attacker could exploit this by sending specially crafted network traffic, leading to compromised system integrity. Th

CVE advisoryCRITICAL

CVE-2026-7858

Teamwork Cloud and Magic Collaboration Studio Deserialization Vulnerability Allows Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in Teamwork Cloud and Magic Collaboration Studio could permit unauthenticated remote code execution. This issue may impact system integrity and confidentiality when the software is network-accessible, potentially allowing unauthorized control.

CVE advisoryCRITICAL

CVE-2026-44825

Apache Solr Hardcoded Credentials Remote Administrative Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Hardcoded default credentials in Apache Solr's authentication setup tool allow remote attackers to gain administrative access. This vulnerability, present when the setup tool is used, could lead to unauthorized control over the Solr cluster. Readers should care because this impacts system integrity and data protection.

CVE advisoryCRITICAL

CVE-2026-42252

Apache Airflow Documentation Shell Metacharacter Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Apache Airflow documentation contained an insecure example for passing parameters when triggering DAGs, which could allow authenticated users to inject shell commands via the DAG's configuration. This vulnerability affects deployments where DAG code was based on this example and users could trigger DAGs, potentially le

CVE advisoryCRITICAL

CVE-2026-48188

OTRS Authentication Bypass via SQL Injection in Database Layer

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper input validation vulnerability in OTRS database layer allows unauthenticated SQL injection, potentially leading to authentication bypass if MySQL/MariaDB uses a specific SQL mode. This could expose sensitive system or user data, impacting systems relying on this OTRS component.