NVD disclosure day

Published threat advisories for June 1, 2026

CVE advisoryKnown Exploit

CVE-2025-48595

Android Integer Overflow Code Execution and Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability in the Android operating system may allow for code execution and local privilege escalation without user interaction. This could impact system data and service behavior. This issue is classified as internal due to its local attack vector.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-49121

AI Tensor Engine ROCm MessageQueue Pickle Deserialization RCE

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in AI Tensor Engine for ROCm allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a MessageQueue.recv() function. This could result in unauthorized commands being run on remote reader workers within a cluster network if attackers can reach the XPUB e

CVE advisoryCRITICAL

CVE-2026-42252

Apache Airflow Documentation Shell Metacharacter Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Apache Airflow documentation contained an insecure example for passing parameters when triggering DAGs, which could allow authenticated users to inject shell commands via the DAG's configuration. This vulnerability affects deployments where DAG code was based on this example and users could trigger DAGs, potentially le

CVE advisoryCRITICAL

CVE-2026-48188

OTRS Authentication Bypass via SQL Injection in Database Layer

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper input validation vulnerability in OTRS database layer allows unauthenticated SQL injection, potentially leading to authentication bypass if MySQL/MariaDB uses a specific SQL mode. This could expose sensitive system or user data, impacting systems relying on this OTRS component.