NVD disclosure day

Published threat advisories for June 5, 2026

CVE advisoryCRITICAL

CVE-2026-11429

Altium Server and Cloud Unauthenticated Arbitrary File Write Leading to RCE.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Altium's Vault Service allows unauthenticated attackers to write arbitrary files to the server, which could lead to remote code execution. This issue affects both Altium Enterprise Server and Altium 365. While Altium Enterprise Server has a patch available, the vulnerability in Altium 365 ha

CVE advisoryCRITICAL

CVE-2026-11423

Altium Enterprise Server Path Traversal Leads to Full System Control

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in the Altium Enterprise Server Collaboration Service allows authenticated users to read arbitrary files. Exploitation could lead to the theft of credentials, granting an attacker full control of the server. Altium 365 cloud deployments are not affected.

CVE advisoryCRITICAL

CVE-2026-45779

Open XDMoD SQL Injection Vulnerability Allows Database Compromise.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability in Open XDMoD, used for analyzing HPC metrics, allows unauthenticated attackers to execute arbitrary SQL commands remotely. This could lead to a complete compromise of the underlying database. All Open XDMoD deployments before version 10.0.3 are affected.

CVE advisoryCRITICAL

CVE-2026-45777

Open XDMoD Command Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Open XDMoD allows remote attackers to execute arbitrary commands on affected servers, potentially leading to data compromise or service disruption. All deployments of Open XDMoD versions 9.5.0 through 11.0.2 are impacted, and immediate review of affected systems is recommended.

CVE advisoryCRITICAL

CVE-2026-45758

Guardrails AI Malicious Package Ingestion

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A malicious version of the Python AI development tool, Guardrails AI, was briefly available on PyPI, posing a risk of system compromise and credential theft to users who installed it. The vulnerability, involving the ingestion of a compromised package, was quickly contained, but organizations should assess exposure and

CVE advisoryCRITICAL

CVE-2026-11420

Altium Enterprise Server Path Traversal and Arbitrary File Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Two path traversal flaws in Altium Enterprise Server's Network Installation Service permit unauthenticated attackers to write arbitrary files to the server or read package archives, potentially enabling remote code execution or disclosure of sensitive data. Altium 365 cloud deployments are unaffected.

CVE advisoryCRITICAL

CVE-2026-11419

Altium Enterprise Server Path Traversal Leading to Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in Altium Enterprise Server allows authenticated users to write arbitrary files to the server. This could lead to remote code execution or service takeover if critical files are overwritten or web-accessible directories are targeted. Altium 365 cloud deployments are not affected.

CVE advisoryCRITICAL

CVE-2026-11414

Altium Enterprise Server Hardcoded Key and Path Traversal Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Altium Enterprise Server could allow an unauthenticated attacker with network access to forge download signatures and read arbitrary files from the server's filesystem. This could lead to the compromise of sensitive server configuration and key material, potentially resulting in full server

CVE advisoryCRITICAL

CVE-2026-46389

UDS Identity Config Client Secret Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A logic error in UDS Identity Config allows attackers to bypass client secret checks, potentially enabling them to authenticate as legitimate clients and obtain OAuth2 tokens. This could lead to unauthorized modification of client configurations. Uncertainty exists regarding specific exploitable configurations and busi

CVE advisoryKnown Exploit

CVE-2026-7473

Arista EOS Tunnel Decapsulation Packet Forwarding Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

On affected Arista EOS platforms with tunnel decapsulation configured, a vulnerability allows the switch to forward unexpected tunneled traffic. This occurs because the switch does not verify the tunnel protocol type when decapsulating packets, potentially leading to the processing of unintended traffic. This issue is

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-9270

DataDog::DogStatsd for Perl Metric Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The DataDog::DogStatsd Perl library has a vulnerability that allows for metric injections due to insufficient input sanitization. This could enable attackers to alter metric names, values, or tags, potentially leading to data corruption or misrepresentation in monitoring systems if the library processes untrusted input

CVE advisoryCRITICAL

CVE-2026-11362

DataDog DogStatsd Perl Metric Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in DataDog::DogStatsd for Perl, versions up to 0.07, allows metric injection through untrusted event tags, potentially corrupting monitoring data. The `format_event` method does not adequately sanitize tag content, enabling attackers to manipulate reported metrics. Its relevance depends on whether syste

CVE advisoryCRITICAL

CVE-2026-10879

Perl DBI Heap Overflow in SQL Statement Preparsing

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap overflow vulnerability exists in Perl's DBI library, triggered when parsing SQL statements with over nine binders. This could allow for denial of service or potentially code execution in applications using this library for database interactions.

CVE advisoryCRITICAL

CVE-2026-6274

Redline WR3200 Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication vulnerability in DTS Electronics Redline WR3200 devices allows unauthenticated attackers to access critical functions. This could lead to unauthorized access, affecting device integrity and potentially disrupting network services. It is uncertain if these devices are in use or exposed to threa

CVE advisoryCRITICAL

CVE-2026-49777

Product Slider Pro for WooCommerce Vulnerability Allows Malicious Software Implant

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Product Slider Pro for WooCommerce plugin due to improper input validation, which could allow attackers to implant malicious software. This issue is reachable via the network and could compromise website integrity and data.

CVE advisoryCRITICAL

CVE-2026-7763

Morse Micro HaLowLink Kernel Driver Heap Overflow Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap-based buffer overflow in a Wi-Fi kernel driver allows an unauthenticated attacker within radio range to cause a denial of service or potentially execute remote code by sending a crafted beacon frame. This issue stems from improper validation of data processed by the driver. The vulnerability could be relevant if

CVE advisoryCRITICAL

CVE-2026-7762

Morse Micro HaLowLink Kernel Driver Heap Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in the Morse Micro HaLow Wi-Fi kernel driver can be triggered by an unauthenticated attacker within radio range using crafted wireless frames, potentially leading to denial of service or remote code execution. This vulnerability could impact systems utilizing Morse Micro HaLowLink 2 softwar

CVE advisoryCRITICAL

CVE-2026-11250

Chrome DevTools Information Disclosure Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An implementation issue in Chrome DevTools may allow a compromised attacker to access sensitive information from process memory via a crafted HTML page. This vulnerability requires prior compromise and user interaction, making it difficult to exploit. Confirm relevance for development teams.