NVD disclosure day

Published threat advisories for June 3, 2026

CVE advisoryCRITICAL

CVE-2026-46244

Linux Kernel Netfilter Transport Header Desync Advisory

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's netfilter component could allow attackers to forge transport headers and bypass firewalls. This occurs due to an incorrect calculation of the transport header offset when processing inner IPv6 packets with extension headers. The issue affects specific Linux kernel versions and coul

CVE advisoryKnown Exploit

CVE-2026-20230

Cisco Unified Communications Manager SSRF Vulnerability Allows Root Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Cisco Unified Communications Manager and Session Management Edition could allow an unauthenticated attacker to write files to the operating system, leading to root privilege escalation. This is due to improper input validation for certain HTTP requests, though exploitation requires the WebDialer serv

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-36748

RockRMS Cross-Site Scripting in User Profiles Affects Social Media Links.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

RockRMS has a cross-site scripting vulnerability in its user profile social media links. This could allow an attacker to execute malicious scripts in a user's browser, potentially leading to unauthorized access to sensitive information or actions performed on behalf of the user. It is uncertain if this technology is us

CVE advisoryCRITICAL

CVE-2026-36576

Openlabs docker-wkhtmltopdf-aas OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability exists in the `app.py` component of openlabs docker-wkhtmltopdf-aas. Attackers can exploit this by sending a crafted POST request, allowing arbitrary command execution. This could impact system integrity and data security.

CVE advisoryCRITICAL

CVE-2026-5241

LightGlue Model Loading Vulnerability in Hugging Face Transformers Allows Arbitrary Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the huggingface/transformers library allows for arbitrary code execution during model initialization, even when remote code execution is disabled. This occurs because untrusted configuration data can override security settings, enabling an attacker to run malicious Python modules when a model is load

CVE advisoryCRITICAL

CVE-2026-35075

Unauthenticated Remote Attacker Recovers Default Password from MBS Solutions Firmware

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated remote attacker can recover a default, hard-coded password from firmware, gaining full access to affected devices. This vulnerability affects various mbs-solutions gateway products. The primary concern is to confirm which devices are relevant and how they are exposed.

CVE advisoryCRITICAL

CVE-2026-47065

Apache MINA deserialization filter bypass and static initializer trigger

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Vulnerabilities in a Java library allow attackers to bypass deserialization filters and trigger static initializers in allow-listed classes, potentially leading to unintended code execution when processing untrusted serialized data. The issues are addressed, but their impact depends on system integration.