NVD disclosure day

Published threat advisories for June 8, 2026

CVE advisoryCRITICAL

CVE-2026-52778

YesWiki Bazar Form Field Calculator Arbitrary Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in YesWiki's form field calculator allows arbitrary PHP code execution due to flawed sanitization of mathematical formulas before they are processed by the `eval()` function. This could lead to server crashes or complete system compromise if reachable.

CVE advisoryCRITICAL

CVE-2026-46289

Linux Kernel Scatterlist Calculation Bug

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's data scattering functions could allow for unintended memory access or manipulation due to incorrect length calculations and potential buffer overlaps. While the specific impact is uncertain, this could lead to system instability or data corruption if the affected internal kernel op

CVE advisoryCRITICAL

CVE-2026-41448

AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie

Halo Surface Signal: 3 out of 5 — possibly public-facing.

AdGuard Home has an authentication bypass vulnerability when started with the `--glinet` flag. Attackers can gain full administrative access by supplying a path traversal sequence in the `Admin-Token` cookie, exploiting unsanitized string concatenation. This could allow unauthorized administrative control of the system

CVE advisoryCRITICAL

CVE-2026-39910

STACKIT IaaS API Privilege Escalation via Service Account Attachment.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the STACKIT IaaS API allows authenticated, low-privileged attackers to escalate privileges and gain full control of an organization's environment. By exploiting a missing authorization check, attackers can attach arbitrary service accounts to virtual machines, retrieve sensitive tokens, and

CVE advisoryCRITICAL

CVE-2026-25555

OpenBullet2 API Key Authentication Bypass Allows Admin Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OpenBullet2 vulnerability allows unauthenticated attackers to bypass authentication by supplying an empty API key, potentially granting them administrative access to the console and all API endpoints. This could enable unauthorized control over the application if it is reachable.

CVE advisoryCRITICAL

CVE-2026-46442

Flowise Authenticated Code Execution via NodeVM Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Flowise, a tool for building large language model flows, allows authenticated users to execute arbitrary JavaScript code, potentially leading to system command execution on the server. This could enable unauthorized control of the Flowise host environment.

CVE advisoryCRITICAL

CVE-2026-46440

Flowise Plaintext Authentication Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Flowise's authentication endpoint, allowing plaintext credential validation without rate limiting. This could enable unauthorized access to the application, potentially compromising custom large language model flows. Organizations should verify the relevance and exposure of their Flow

CVE advisoryCRITICAL

CVE-2026-44631

Apache HTTP Server Regular Expression Buffer Underwrite Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A buffer underwrite vulnerability exists in Apache HTTP Server when processing crafted regular expressions in its configuration. This could potentially allow an unauthenticated attacker to impact server integrity and availability by overwriting memory, leading to unexpected behavior or system compromise. It is recommen

CVE advisoryCRITICAL

CVE-2026-42535

Apache HTTP Server mod_dav_fs Path Handling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path handling flaw in Apache's mod_dav_fs allows content authors to directly manipulate trusted DAV property databases, potentially causing child process crashes. This vulnerability affects Apache HTTP Server versions prior to 2.4.68 and is relevant for systems utilizing WebDAV for file sharing or content management.

CVE advisoryCRITICAL

CVE-2026-29167

Apache HTTP Server mod_ldap Use After Free Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A Use After Free vulnerability in Apache HTTP Server's mod_ldap module could allow an unauthenticated attacker to execute arbitrary code or cause a denial of service. This affects widely used internet-facing applications, potentially impacting service availability and integrity.

CVE advisoryKnown Exploit

CVE-2026-50751

Check Point Security Gateway IKEv1 Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A logic flow weakness in certificate validation within a deprecated VPN protocol allows unauthenticated remote attackers to bypass user authentication and establish unauthorized VPN connections without a password. The relevance of this vulnerability depends on the use of this specific deprecated protocol for remote or

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-47430

InAppBrowser Callback Spoofing Vulnerability in Cordova Plugin

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the InAppBrowser component of Apache Cordova allows an attacker controlling web content to spoof plugin results by triggering arbitrary callbacks. This could lead to actions such as forged camera approvals or fabricated contact lists, impacting applications that load external web content. The issue r

CVE advisoryCRITICAL

CVE-2026-11499

Tenda HG7HG9 HG10 Stack Buffer Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Tenda gateway devices allows remote attackers to cause a stack-based buffer overflow via crafted requests to a web interface function. This could compromise device functions, potentially disrupting network connectivity. The primary concern is determining if these Tenda devices are present an

CVE advisoryCRITICAL

CVE-2024-58348

WordPress Background Image Cropper Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a WordPress plugin, enabling unauthenticated attackers to upload arbitrary files. If reachable, this could allow for arbitrary code execution on the server, posing a risk to website integrity and operation. The presence and accessibility of this plugin on your WordPress deployments sh

CVE advisoryCRITICAL

CVE-2023-54352

WordPress Seotheme Unauthenticated Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability exists in the WordPress Seotheme, allowing unauthenticated attackers to upload and execute malicious PHP files. This could lead to unauthorized system command execution and persistent access to affected WordPress sites.