NVD disclosure day

Published threat advisories for June 4, 2026

CVE advisoryCRITICAL

CVE-2026-48567

Azure HorizonDB Authentication Bypass Vulnerability Allows Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in Azure HorizonDB, potentially allowing unauthorized network access and privilege escalation. This could lead to unauthorized access, modification, or deletion of sensitive data if the technology is deployed and reachable.

CVE advisoryKnown Exploit

CVE-2026-20245

Cisco Catalyst SD-WAN Manager Local Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Cisco Catalyst SD-WAN Manager's CLI could allow an authenticated, local attacker to run commands as root by providing a malicious file. This could lead to command injection and privilege escalation on the affected system. The issue is due to insufficient input validation and requires netadmin privile

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-11213

Chrome Reading Mode Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's Reading Mode allows a remote attacker, who has already compromised the renderer process, to potentially escape the browser's sandbox via a crafted HTML page. This could lead to broader system compromise if a user visits such a page. The uncertainty lies in the specific conditions requ

CVE advisoryCRITICAL

CVE-2026-11198

Google Chrome Sandbox Escape via Malicious Video File

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's video processing, due to insufficient input validation, could allow a remote attacker to escape the browser sandbox by tricking a user into opening a crafted video file. While exploitation requires user interaction and is assessed as having a very low likelihood of impacting the organ

CVE advisoryCRITICAL

CVE-2026-11167

Google Chrome for Android WebView Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Android's Google Chrome WebView could allow a compromised renderer process to escape the sandbox, potentially affecting system integrity. The primary concern is confirming if this client-side technology is in use and relevant to your environment.

CVE advisoryCRITICAL

CVE-2026-11165

Chrome iOS WebMIDI Sandbox Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Chrome's WebMIDI component on iOS allows a remote attacker to potentially escape the browser's sandbox via a crafted HTML page. This issue is classified as critical and affects a widely used web browser, posing a risk if users access malicious content. The vulnerability could lead to b

CVE advisoryCRITICAL

CVE-2026-11163

Chrome for Android Sandbox Escape via Malicious HTML.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome on Android allows remote attackers to escape the sandbox via a crafted HTML page. This could potentially lead to unauthorized access to sensitive data or system functions on affected devices. The vulnerability requires user interaction with a malicious website and may impact con

CVE advisoryCRITICAL

CVE-2026-11153

Google Chrome Cross-Origin Data Leakage via Side Channel

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A side-channel vulnerability in Google Chrome enables attackers to leak cross-origin data through malicious web pages. This could potentially expose sensitive information from other websites to an attacker if a user visits a crafted HTML page. Understanding the presence and usage of affected Chrome versions is importan

CVE advisoryCRITICAL

CVE-2026-11146

Google Chrome Chromoting Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's Chromoting feature allows a remote attacker, who has already compromised the renderer process, to escape the browser's sandbox by tricking a user into visiting a crafted HTML page. This could potentially lead to unauthorized access to sensitive information or further system compromise

CVE advisoryCRITICAL

CVE-2026-11131

Chrome for Android Autofill Sandbox Escape Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome for Android's Autofill feature could allow an attacker who has compromised the renderer process to escape the browser's sandbox via a specially crafted HTML page. This could potentially affect user data and services.

CVE advisoryCRITICAL

CVE-2026-11114

Chrome Device Trust Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Chrome's Device Trust feature on Mac, potentially allowing an attacker who has compromised the renderer process to escape the browser's sandbox via a crafted HTML page. This could affect sensitive information or system behavior.

CVE advisoryCRITICAL

CVE-2026-11113

ANGLE Sandbox Escape in Google Chrome

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's ANGLE component could allow a remote attacker to escape the browser's sandbox via a malicious HTML page. If reachable, this could lead to the compromise of the renderer process and potentially the user's system. It is important to confirm if this component is relevant to your organiza

CVE advisoryCRITICAL

CVE-2026-11112

Chromoting Sandbox Escape Vulnerability in Google Chrome on Linux

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome on Linux allows a remote attacker who has compromised the renderer process to potentially escape the browser's sandbox via a crafted Chrome Extension. This could lead to unauthorized access to the underlying Linux system if the Chromoting component is reachable or relevant.

CVE advisoryCRITICAL

CVE-2026-11100

Google Chrome Use After Free Sandbox Escape on macOS

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on macOS could allow a remote attacker to escape the browser's sandbox. Exploitation requires a user to interact with specific UI elements on a crafted HTML page, potentially exposing sandbox process data. The reader should care if their organization uses Chrome on macOS,

CVE advisoryCRITICAL

CVE-2026-11095

Chrome Sandbox Escape Vulnerability via Malicious HTML

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's Codecs allows a remote attacker, who has compromised the renderer process, to potentially escape the browser's sandbox by using a specially crafted HTML page. This could lead to unauthorized access to system resources. The risk is present if users access untrusted websites.

CVE advisoryCRITICAL

CVE-2026-11094

Chrome Codec Use After Free Sandbox Escape.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on Windows could allow a remote attacker to escape the browser sandbox via a crafted HTML page, potentially exposing protected data. This issue requires the attacker to have already compromised the renderer process and for the user to interact with malicious content.

CVE advisoryCRITICAL

CVE-2026-11088

ANGLE Integer Overflow in Chrome Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability exists in ANGLE, a component within Google Chrome. If reachable, a remote attacker could exploit this to escape the browser's sandbox, potentially affecting system access and data. The relevance of this vulnerability depends on user interaction with a crafted HTML page.

CVE advisoryCRITICAL

CVE-2026-11082

Google Chrome for Android Sandbox Escape via GPU Race Condition

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome on Android's GPU component could allow a sandboxed attacker to escape, potentially impacting the device. This requires an attacker to first compromise the renderer process and then trick a user into visiting a crafted HTML page. The relevance and exposure to Android Chrome users should

CVE advisoryCRITICAL

CVE-2026-11070

Chrome Chromoting Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Google Chrome on Windows has a vulnerability where insufficient input validation in Chromoting could allow a network-compromised attacker to escape the browser's sandbox via malicious network traffic. This requires a pre-existing compromise and is not directly reachable from the internet.

CVE advisoryCRITICAL

CVE-2026-11066

ANGLE Sandbox Escape Vulnerability in Google Chrome

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ANGLE within Google Chrome may permit a remote attacker to escape the browser sandbox via a malicious HTML page. While exploitation requires user interaction, web browsers are constantly exposed to untrusted content, making this a relevant risk. The potential impact, if exploited, could involve broad

CVE advisoryCRITICAL

CVE-2026-11065

Google Chrome ANGLE Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in Google Chrome's ANGLE component may allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This vulnerability could potentially lead to broader system compromise if a user visits a malicious webpage. The extent of data or system impact is uncertain.

CVE advisoryCRITICAL

CVE-2026-11043

Chrome ANGLE Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write in ANGLE, used by Google Chrome on macOS, allows a remote attacker who has compromised the renderer process to potentially escape the browser sandbox via a crafted HTML page. This vulnerability could allow broader system compromise, and its relevance depends on user interaction with malicious con

CVE advisoryCRITICAL

CVE-2026-11029

Google Chrome for Android Drag and Drop Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Insufficient validation in Chrome for Android's Drag and Drop feature allows a compromised renderer process to potentially escape the sandbox via a crafted HTML page. This could enable an attacker to execute code with higher privileges on a user's device. The relevance hinges on user interaction with malicious websites

CVE advisoryCRITICAL

CVE-2026-11021

Google Chrome GPU Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Insufficient validation in Google Chrome's GPU component allows a remote attacker, who has compromised the renderer process, to potentially escape the sandbox via a crafted HTML page. This could impact system confidentiality, integrity, and availability if a user interacts with such a page.

CVE advisoryCRITICAL

CVE-2026-10990

Chrome Glic Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Glic component may allow a remote attacker to escape the browser's sandbox. Exploitation requires a user to visit a malicious HTML page, and the vulnerability is in the client-side browser process. The reader should care to confirm if their organization uses the affecte

CVE advisoryCRITICAL

CVE-2026-10972

Chrome Ozone Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Google Chrome's Ozone component on Linux, potentially allowing a remote attacker to escape the browser sandbox via a malicious HTML page. This means an attacker could gain elevated privileges on the affected system. Confirmation of Chrome on Linux usage is needed to assess relev

CVE advisoryCRITICAL

CVE-2026-10931

Google Chrome Sandbox Escape via Use After Free in File System

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's File System component could allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This could potentially affect the integrity and confidentiality of system resources accessible from within the sandbox. While exploitation requires user interact

CVE advisoryCRITICAL

CVE-2026-10892

Chrome for Android GPU Out of Bounds Write Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome on Android, specifically an out-of-bounds write in the GPU component, could allow a remote attacker to bypass sandbox protections via a crafted HTML page. This could potentially lead to broader system compromise or data exposure. The relevance hinges on the presence and usage o

CVE advisoryCRITICAL

CVE-2026-10886

Chrome FileSystem Use After Free Sandbox Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's FileSystem could allow a remote attacker to escape the browser sandbox via a crafted HTML page. This could potentially lead to broader system compromise, making it important to understand if affected systems are reachable or relevant.

CVE advisoryCRITICAL

CVE-2026-10881

Chrome ANGLE Out-of-Bounds Read/Write Vulnerability Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in ANGLE, a component of Google Chrome, could permit a remote attacker to escape the browser's sandbox by presenting a specially crafted HTML page. This could potentially affect user data or system behavior within the sandbox. Its relevance is dependent on user interaction with malicious websites.

CVE advisoryCRITICAL

CVE-2025-71316

SQLite sqldiff DLL Load via Windows ANSI Conversion

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in SQLite's `sqldiff.exe` on Windows allows an attacker to load arbitrary DLLs by exploiting how the Windows C runtime converts Unicode to ANSI characters with a crafted command line. This could lead to unauthorized code execution if the utility misinterprets command-line file arguments as options.

CVE advisoryCRITICAL

CVE-2026-50292

libinput Udev Property Injection Vulnerability Allows Root Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in libinput, a library for handling input devices, could permit root code execution by injecting unescaped udev properties. This could lead to system compromise if exploited, making it important to confirm libinput's presence and relevance in the environment.

CVE advisoryCRITICAL

CVE-2026-25550

Seagull Software BarTender .NET Remoting Service Unauthenticated Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Seagull Software BarTender's .NET Remoting service, potentially allowing unauthenticated remote attackers to execute arbitrary code or steal credentials. The service, running on TCP port 7375, is network-accessible and can lead to sensitive data disclosure or further network intrusion

CVE advisoryCRITICAL

CVE-2026-10880

OSNexus QuantaStor SDS Manager SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A SQL injection vulnerability in OSNexus QuantaStor SDS Manager's login endpoint allows unauthenticated remote attackers to bypass authentication and gain administrator access. If the login endpoint is reachable, an attacker could potentially control the storage system without a valid password. This is a critical vulne

CVE advisoryCRITICAL

CVE-2025-67447

Neterbit Router NW-431F OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in the network diagnosis module of Neterbit NW-431F Routers, allowing unauthenticated attackers to execute arbitrary commands with web server privileges by manipulating the ping feature's IP address input. This could impact network operations and security, warranting

CVE advisoryCRITICAL

CVE-2025-67446

Neterbit NW-431F Router Authentication Bypass via Predictable Cookie

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authentication bypass vulnerability exists in Neterbit NW-431F routers, enabling attackers to gain unauthorized administrative access by manipulating a predictable cookie. This could allow attackers to modify router settings when the device is network-reachable.

CVE advisoryCRITICAL

CVE-2026-43986

Tautulli SSRF via Unauthenticated Image Proxying

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Tautulli, a Plex Media Server monitoring tool, allows unauthenticated users to trigger server-side requests to arbitrary URLs. This could expose internal network resources or services. An attacker can make the Tautulli host fetch any attacker-chosen URL by seeding a malicious image URL and t

CVE advisoryCRITICAL

CVE-2026-36182

GNCC GP5 Weak Hashing Algorithm Exposes Root Credentials.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

GNCC GP5 has a vulnerability where a weak hashing algorithm is used to protect the root password, potentially allowing unauthorized access to root credentials and privileges via bruteforce. This is relevant because GNCC GP5 is a network management technology commonly deployed as an edge service, making it a likely targ

CVE advisoryCRITICAL

CVE-2026-10868

MISP User Edit Mass Assignment Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A mass assignment vulnerability in the MISP user edit function allows an authenticated attacker to modify unintended user accounts by manipulating request data. This flaw, stemming from insufficient filtering of user-supplied fields, could lead to unauthorized alterations of user account attributes and compromise accou

CVE advisoryCRITICAL

CVE-2026-35906

T3 Technology CPE Debug CGI Command Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An undocumented debug endpoint in T3 Technology CPE models allows unauthenticated attackers to execute arbitrary system commands as root. This vulnerability is reachable via HTTP with a crafted query string, potentially impacting device integrity and availability. Organizations should confirm if affected devices are in

CVE advisoryCRITICAL

CVE-2026-35905

T3 Technology CPE Devices Hardcoded Root Password Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Certain T3 Technology CPE devices contain a hardcoded password for root access, allowing unauthenticated attackers to gain complete administrative control. This could compromise network security and operations if these devices are internet-facing.

CVE advisoryCRITICAL

CVE-2026-35904

T3 CPE Models Telnet Enablement Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability in the web management interface of T3 Technology CPE models allows unauthenticated attackers to enable the Telnet service. If reachable, this could expose sensitive data and grant unauthorized access to the device's operating system. It is important to identify affected devices and asses

CVE advisoryCRITICAL

CVE-2019-25741

MobaXterm Session File Buffer Overflow Allows Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow vulnerability exists in MobaXterm's handling of session files, specifically within the username field. If a user imports a maliciously crafted session file, an attacker could execute arbitrary code with user privileges on the affected system. This issue is relevant if MobaXterm is in use and users mig

CVE advisoryCRITICAL

CVE-2019-25738

WordPress Hybrid Composer Unauthenticated Settings Change Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated settings change vulnerability exists in WordPress Hybrid Composer, allowing attackers to modify critical site options by exploiting the `hc_ajax_save_option` action. This could enable user registration and set the default role to administrator, leading to account takeover. Uncertainty exists regardin

CVE advisoryCRITICAL

CVE-2019-25729

PDF Signer Server-Side Template Injection RCE via CSRF Cookie

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side template injection vulnerability exists in PDF Signer, allowing unauthenticated attackers to execute arbitrary code by injecting PHP commands through a cookie. This could lead to unauthorized access to sensitive information on affected servers. Confirming the use and external exposure of this technology i

CVE advisoryCRITICAL

CVE-2019-25727

WordPress Plugin ad manager wd Arbitrary File Download Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can download sensitive files from a WordPress plugin by exploiting an arbitrary file download vulnerability through crafted GET requests. This could expose critical configuration data if the plugin is reachable and relevant to your organization.

CVE advisoryCRITICAL

CVE-2026-50214

Plan Service Token Vulnerability Allows Arbitrary Network Plan Creation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a network service that manages internet plans, allowing for arbitrary creation of zero-cost plans due to a shared, unprotected API token. This could lead to unauthorized network access and resource consumption if reachable. Readers should confirm the relevance and exposure of this service with

CVE advisoryCRITICAL

CVE-2026-50208

TrustAllCerts Routine and Hardcoded Keys Enable Network Traffic Decryption.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in networking devices where routines disable standard TLS certificate validation and hard-coded encryption keys are used. This allows a man-in-the-middle attacker to decrypt network traffic, potentially exposing sensitive information.

CVE advisoryCRITICAL

CVE-2026-49194

Acer Connect M6E 5G Debugging Flaw Bypasses Login for Shell Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Acer Connect M6E 5G firmware, allowing a low-privilege attacker to bypass login prompts and gain direct access to an interactive shell. This could enable unauthorized control over devices providing internet connectivity. Organizations should determine if they use this technology and a

CVE advisoryCRITICAL

CVE-2026-49191

M3WebServer API Key Hardcoding Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The M3WebServer hard-codes backend API keys that can be intercepted via error pages, potentially allowing unauthorized access to sensitive data and backend services. This vulnerability is considered critical and affects internet-facing devices, necessitating confirmation of relevance and exposure across your environmen

CVE advisoryCRITICAL

CVE-2026-49190

Acer Connect M6E 5G Firmware Instruction Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Acer Connect M6E 5G firmware, allowing unauthorized application installations or command executions by bypassing instruction permission checks. This could lead to system compromise if the affected technology is reachable.

CVE advisoryCRITICAL

CVE-2026-49185

FieldX MDM Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The FieldX MDM software has a critical vulnerability allowing unverified commands to be executed directly through its adb messaging topic. This command injection flaw could enable an unauthenticated attacker to run arbitrary commands, potentially leading to unauthorized system access or data compromise. Organizations u