NVD disclosure day

Published threat advisories for June 2, 2026

CVE advisoryCRITICAL

CVE-2026-35482

alf.io Administrator Sandbox Escape Vulnerability Allows OS Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A sandbox escape vulnerability in alf.io's extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server. This could impact the confidentiality, integrity, and availability of the server.

CVE advisoryCRITICAL

CVE-2026-32625

LibreChat Server Information Disclosure Risk

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated user can exploit a vulnerability in LibreChat's server integration to expose sensitive credentials. This could lead to a compromise of cryptographic materials and database access for the affected organization. The risk involves unauthorized access to critical business data.

CVE advisoryCRITICAL

CVE-2026-38967

CrowCpp Response Header Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

CrowCpp HTTP response header injection allows unvalidated header values to be manipulated, potentially leading to attacks like XSS or cache poisoning. This vulnerability, affecting CrowCpp up to version 1.3.1, poses a critical risk to the integrity and availability of web services and user interactions. It is uncertain

CVE advisoryCRITICAL

CVE-2026-42074

OpenClaude Command Injection Vulnerability Allows Host-Level Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The OpenClaude command-line interface, prior to version 0.5.1, contains a vulnerability where a model can bypass security sandboxing and execute arbitrary commands on the host system. This occurs when a prompt-injected model is able to set a parameter to disable the sandbox, especially with default configurations that

CVE advisoryCRITICAL

CVE-2026-0611

Spacelabs Sentinel Unauthenticated Remote Code Execution via .NET Remoting

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Spacelabs Healthcare Sentinel systems may allow unauthenticated attackers to execute arbitrary code remotely through a deprecated .NET Remoting channel if port 8989 is intentionally network-accessible. This could enable attackers to read and write files, potentially leading to remote code execution.

CVE advisoryCRITICAL

CVE-2026-47117

OpenMed PII Privacy Filter Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenMed's PII privacy-filter model loading path contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code with the service's privileges. This occurs when a malicious model repository is supplied via the `model_name` parameter. The core concern is to determine if this

CVE advisoryCRITICAL

CVE-2026-7198

Progress Sitefinity Improper Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Progress Sitefinity web services permits unauthenticated remote attackers to access restricted content. This can result in a complete compromise of confidentiality, integrity, and availability for affected installations when reachable.

CVE advisoryCRITICAL

CVE-2026-42684

WP Job Portal Blind SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A blind SQL injection vulnerability exists in the WP Job Portal, potentially allowing unauthenticated attackers to manipulate database queries over the network and access sensitive information. The risk involves unauthorized data access and system compromise. Confirming the use and exposure of this product is crucial f

CVE advisoryCRITICAL

CVE-2026-34906

Wirtualna Uczelnia Server-Side Template Injection Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Server-Side Template Injection vulnerability in Wirtualna Uczelnia allows unauthenticated attackers to execute remote code. Insufficient input validation in URL redirection parameters enables attackers to inject and execute arbitrary template expressions on the server, potentially leading to command executio

CVE advisoryCRITICAL

CVE-2026-8206

Kirki WordPress Plugin Account Takeover Via Email Reset Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Kirki WordPress plugin has a critical privilege escalation vulnerability. Unauthenticated attackers can exploit this by sending password reset links to their own email addresses, leading to account takeovers. This could allow unauthorized access and modification of website content or user data.