NVD disclosure day

Published threat advisories for June 9, 2026

CVE advisoryCRITICAL

CVE-2026-44963

Remote Code Execution in Backup Server for Authenticated Domain Users

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability allows an authenticated domain user to execute arbitrary code on the Backup Server, potentially impacting the confidentiality, integrity, and availability of backup data and services. This issue requires an authenticated domain user to exploit, and infrastructure or security teams are likely re

CVE advisoryCRITICAL

CVE-2026-48303

Adobe Campaign Classic Incorrect Authorization Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is affected by an incorrect authorization vulnerability enabling arbitrary code execution without user interaction. Attackers can exploit this over the network, potentially leading to a broad compromise of the user's context. This issue is critical as it bypasses security layers and can be trigge

CVE advisoryCRITICAL

CVE-2026-47938

Adobe Campaign Classic SSRF Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Request Forgery vulnerability in Adobe Campaign Classic could allow unauthorized code execution without user interaction, changing the scope of impact. This issue is reachable externally and could lead to arbitrary code execution. Security-aware leaders should assess their Adobe Campaign Classic instances

CVE advisoryCRITICAL

CVE-2026-36727

bookcars v8.3 Social Sign-In Authentication Bypass via Forged JWT Token

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in a social sign-in endpoint could allow unauthorized access via a forged token. This critical issue may lead to exposure of system data. Confirmation of the technology's use and exposure within the environment is necessary.

CVE advisoryCRITICAL

CVE-2026-36721

Bookcars JWT Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in bookcars' `validateAccessToken` function allows attackers to bypass authentication by submitting a forged JWT token. This could lead to unauthorized access to application functions and potentially sensitive information. Determining if bookcars is used within the environment is the primary concern.

CVE advisoryCRITICAL

CVE-2026-30141

AnimatedGIF LZW Decode Buffer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow in the LZW Decode function of the AnimatedGIF software library can be exploited by a remote attacker providing a crafted GIF file. This vulnerability could lead to a denial of service, causing an application crash, or potentially allow for arbitrary code execution. The impact is significant if the aff

CVE advisoryCRITICAL

CVE-2026-10045

Kangda Xin DR300 Router Hardcoded Credentials and Telnet Enable Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Shenzhen Kangda Xin Intelligent Network Technology Company routers due to hardcoded credentials and default Telnet access. This allows unauthenticated attackers to read/write memory, modify firmware, and inspect network activity, posing a significant security risk. The vulnerability i

CVE advisoryMEDIUM

CVE-2026-34691

Adobe Experience Manager Forms Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Experience Manager Forms is affected by a stored Cross-Site Scripting vulnerability that allows attackers to inject malicious scripts into form fields. If a victim views a page with a vulnerable field, these scripts could execute in their browser, potentially leading to unauthorized access or control over their a

CVE advisoryCRITICAL

CVE-2026-49841

FreeSWITCH mod_verto Heap Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap overflow vulnerability exists in FreeSWITCH's mod_verto component, allowing unauthenticated network access to exploit an attacker-controlled memory corruption before authentication checks. This could lead to impacts on data integrity and service availability.

CVE advisoryCRITICAL

CVE-2026-49840

FreeSWITCH ESL Heap Corruption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in FreeSWITCH's Event Socket Layer could allow an unauthenticated attacker to crash services or corrupt memory by sending a malicious frame with a negative content length. This could impact the availability and integrity of telecom systems before authentication. Understanding FreeSWITCH deployments and

CVE advisoryCRITICAL

CVE-2026-47643

Azure Stack Edge External Control of File Name Vulnerability Allows Network Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An external control of file name or path vulnerability in Azure Stack Edge could allow an unauthorized attacker to execute code over a network. This issue could impact the confidentiality, integrity, and availability of affected systems. As Azure Stack Edge devices often operate at the network edge and interact with ex

CVE advisoryCRITICAL

CVE-2026-47281

Visual Studio Code Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An improper input validation vulnerability in Visual Studio Code could allow an unauthorized attacker to elevate privileges over a network. While the application is typically used locally, its reachability and potential impact on system integrity and availability are key concerns. The primary need is to confirm if this

CVE advisoryCRITICAL

CVE-2026-45657

Windows Kernel Use-After-Free Allows Network Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability in the Windows Kernel allows an unauthorized attacker to execute code over a network. This critical flaw could lead to remote code execution, potentially impacting system integrity and availability. It is uncertain if the affected technology is present or reachable within our environment.

CVE advisoryCRITICAL

CVE-2026-45602

Windows DHCP Server Network Tampering Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A network tampering vulnerability in Windows DHCP Server could allow an unauthorized attacker to modify data without authentication. This could impact network stability and traffic redirection, necessitating confirmation of its presence and exposure within the environment.

CVE advisoryHIGH

CVE-2026-45447

OpenSSL PKCS#7 Signature Verification Use-After-Free.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in OpenSSL related to PKCS#7 signature verification could allow a specially crafted message to trigger a use-after-free, potentially leading to process crashes, memory corruption, or remote code execution. This issue may affect applications processing PKCS#7 or S/MIME signed messages using OpenSSL's PKC

CVE advisoryCRITICAL

CVE-2026-44815

Windows DHCP Client Stack Buffer Overflow Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical stack-based buffer overflow vulnerability in the Windows DHCP Client enables unauthorized network attackers to execute code. This could compromise affected systems, impacting data confidentiality, integrity, and availability. Understanding this threat is vital for assessing environmental risks.

CVE advisoryCRITICAL

CVE-2026-38615

DedeCMS V5.7.118 Command Execution in file_manage_control.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command execution vulnerability exists in DedeCMS's file management functionality, potentially allowing unauthenticated network access to execute arbitrary commands on affected systems. This could lead to a complete system compromise, impacting data integrity and availability, making it crucial to identify a

CVE advisoryCRITICAL

CVE-2026-34182

OpenSSL CMS AuthEnvelopedData Validation Bypass and Key Equivalence Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in cryptographic message processing may allow attackers to bypass integrity checks or gain key-equivalent functionality. This issue affects how authenticated enveloped data containers are validated, potentially enabling unauthorized access to encryption keys or modification of messages. The FIPS modules

CVE advisoryCRITICAL

CVE-2026-26142

Nuance PowerScribe Network Code Execution via Untrusted Data Deserialization.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Nuance PowerScribe allows unauthorized remote code execution over a network due to untrusted data deserialization. If reachable, this could compromise system integrity and data. Understanding if your organization uses this technology and its network exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-8025

CBS Platform SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in CBS Platform. Attackers can manipulate database commands, potentially leading to unauthorized access or data modification. This issue is particularly concerning as the platform is no longer supported by the vendor, implying a lack of security updates. The primary concern

CVE advisoryCRITICAL

CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability in Fortinet FortiSandbox may allow an unauthenticated attacker to execute unauthorized commands. This could impact the functionality and security of network security devices if reachable via specially crafted HTTP requests.

CVE advisoryCRITICAL

CVE-2026-10523

Ivanti Sentry Authentication Bypass Enables Full Administrative Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in Ivanti Sentry could allow an unauthenticated remote attacker to create arbitrary administrative accounts and gain full administrative access. This issue is relevant if Ivanti Sentry is used and accessible.

CVE advisoryKnown Exploit

CVE-2026-10520

Ivanti Sentry OS Command Injection Leads to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability in Ivanti Sentry could allow an unauthenticated remote attacker to execute code at the root level. This issue is critical because Ivanti Sentry is often internet-facing, potentially exposing organizations to significant compromise.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-11638

Chrome Sandbox Escape Vulnerability in Printing

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Google Chrome's printing component, potentially allowing a remote attacker to escape the browser's sandbox through a crafted HTML page. This critical flaw requires user interaction to exploit, raising concerns about relevance and exposure.