NVD disclosure day

Published threat advisories for June 5, 2026

CVE advisoryCRITICAL

CVE-2026-45779

Open XDMoD SQL Injection Vulnerability Allows Database Compromise.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability in Open XDMoD, used for analyzing HPC metrics, allows unauthenticated attackers to execute arbitrary SQL commands remotely. This could lead to a complete compromise of the underlying database. All Open XDMoD deployments before version 10.0.3 are affected.

CVE advisoryCRITICAL

CVE-2026-45777

Open XDMoD Command Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Open XDMoD allows remote attackers to execute arbitrary commands on affected servers, potentially leading to data compromise or service disruption. All deployments of Open XDMoD versions 9.5.0 through 11.0.2 are impacted, and immediate review of affected systems is recommended.

CVE advisoryKnown Exploit

CVE-2026-7473

Arista EOS Tunnel Decapsulation Packet Forwarding Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

On affected Arista EOS platforms with tunnel decapsulation configured, a vulnerability allows the switch to forward unexpected tunneled traffic. This occurs because the switch does not verify the tunnel protocol type when decapsulating packets, potentially leading to the processing of unintended traffic. This issue is

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-9270

DataDog::DogStatsd for Perl Metric Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The DataDog::DogStatsd Perl library has a vulnerability that allows for metric injections due to insufficient input sanitization. This could enable attackers to alter metric names, values, or tags, potentially leading to data corruption or misrepresentation in monitoring systems if the library processes untrusted input

CVE advisoryCRITICAL

CVE-2026-11362

DataDog DogStatsd Perl Metric Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in DataDog::DogStatsd for Perl, versions up to 0.07, allows metric injection through untrusted event tags, potentially corrupting monitoring data. The `format_event` method does not adequately sanitize tag content, enabling attackers to manipulate reported metrics. Its relevance depends on whether syste