NVD disclosure day

Published threat advisories for June 9, 2026

CVE advisoryCRITICAL

CVE-2026-44963

Remote Code Execution in Backup Server for Authenticated Domain Users

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability allows an authenticated domain user to execute arbitrary code on the Backup Server, potentially impacting the confidentiality, integrity, and availability of backup data and services. This issue requires an authenticated domain user to exploit, and infrastructure or security teams are likely re

CVE advisoryCRITICAL

CVE-2026-48303

Adobe Campaign Classic Incorrect Authorization Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is affected by an incorrect authorization vulnerability enabling arbitrary code execution without user interaction. Attackers can exploit this over the network, potentially leading to a broad compromise of the user's context. This issue is critical as it bypasses security layers and can be trigge

CVE advisoryCRITICAL

CVE-2026-47938

Adobe Campaign Classic SSRF Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Request Forgery vulnerability in Adobe Campaign Classic could allow unauthorized code execution without user interaction, changing the scope of impact. This issue is reachable externally and could lead to arbitrary code execution. Security-aware leaders should assess their Adobe Campaign Classic instances

CVE advisoryCRITICAL

CVE-2026-47932

Adobe ColdFusion Path Traversal Vulnerability Allows Security Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe ColdFusion has a Path Traversal vulnerability that could allow a security feature bypass. If reachable, an attacker could trick a user into opening a malicious file to access unauthorized files or directories, changing the scope of what they can reach. This is relevant due to ColdFusion's role as a web applicatio

CVE advisoryCRITICAL

CVE-2026-47929

Adobe ColdFusion Authorization Flaw Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Incorrect Authorization vulnerability in Adobe Cold Fusion could permit a high-privileged attacker to execute arbitrary code, potentially gaining elevated access or control over a user's account or session without requiring user interaction. This could lead to system compromise if the vulnerability is reachable.

CVE advisoryCRITICAL

CVE-2026-36727

bookcars v8.3 Social Sign-In Authentication Bypass via Forged JWT Token

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in a social sign-in endpoint could allow unauthorized access via a forged token. This critical issue may lead to exposure of system data. Confirmation of the technology's use and exposure within the environment is necessary.

CVE advisoryCRITICAL

CVE-2026-36721

Bookcars JWT Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in bookcars' `validateAccessToken` function allows attackers to bypass authentication by submitting a forged JWT token. This could lead to unauthorized access to application functions and potentially sensitive information. Determining if bookcars is used within the environment is the primary concern.

CVE advisoryCRITICAL

CVE-2026-30141

AnimatedGIF LZW Decode Buffer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow in the LZW Decode function of the AnimatedGIF software library can be exploited by a remote attacker providing a crafted GIF file. This vulnerability could lead to a denial of service, causing an application crash, or potentially allow for arbitrary code execution. The impact is significant if the aff

CVE advisoryCRITICAL

CVE-2026-10045

Kangda Xin DR300 Router Hardcoded Credentials and Telnet Enable Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Shenzhen Kangda Xin Intelligent Network Technology Company routers due to hardcoded credentials and default Telnet access. This allows unauthenticated attackers to read/write memory, modify firmware, and inspect network activity, posing a significant security risk. The vulnerability i

CVE advisoryCRITICAL

CVE-2026-34691

Adobe Experience Manager Forms Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Experience Manager Forms is affected by a stored Cross-Site Scripting vulnerability that allows attackers to inject malicious scripts into form fields. If a victim views a page with a vulnerable field, these scripts could execute in their browser, potentially leading to unauthorized access or control over their a

CVE advisoryCRITICAL

CVE-2026-49841

FreeSWITCH mod_verto Heap Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap overflow vulnerability exists in FreeSWITCH's mod_verto component, allowing unauthenticated network access to exploit an attacker-controlled memory corruption before authentication checks. This could lead to impacts on data integrity and service availability.

CVE advisoryCRITICAL

CVE-2026-49840

FreeSWITCH ESL Heap Corruption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in FreeSWITCH's Event Socket Layer could allow an unauthenticated attacker to crash services or corrupt memory by sending a malicious frame with a negative content length. This could impact the availability and integrity of telecom systems before authentication. Understanding FreeSWITCH deployments and

CVE advisoryCRITICAL

CVE-2026-47643

Azure Stack Edge External Control of File Name Vulnerability Allows Network Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An external control of file name or path vulnerability in Azure Stack Edge could allow an unauthorized attacker to execute code over a network. This issue could impact the confidentiality, integrity, and availability of affected systems. As Azure Stack Edge devices often operate at the network edge and interact with ex

CVE advisoryCRITICAL

CVE-2026-47281

Visual Studio Code Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An improper input validation vulnerability in Visual Studio Code could allow an unauthorized attacker to elevate privileges over a network. While the application is typically used locally, its reachability and potential impact on system integrity and availability are key concerns. The primary need is to confirm if this

CVE advisoryCRITICAL

CVE-2026-45657

Windows Kernel Use-After-Free Allows Network Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability in the Windows Kernel allows an unauthorized attacker to execute code over a network. This critical flaw could lead to remote code execution, potentially impacting system integrity and availability. It is uncertain if the affected technology is present or reachable within our environment.

CVE advisoryCRITICAL

CVE-2026-45602

Windows DHCP Server Network Tampering Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A network tampering vulnerability in Windows DHCP Server could allow an unauthorized attacker to modify data without authentication. This could impact network stability and traffic redirection, necessitating confirmation of its presence and exposure within the environment.

CVE advisoryHIGH

CVE-2026-45447

OpenSSL PKCS#7 Signature Verification Use-After-Free.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in OpenSSL related to PKCS#7 signature verification could allow a specially crafted message to trigger a use-after-free, potentially leading to process crashes, memory corruption, or remote code execution. This issue may affect applications processing PKCS#7 or S/MIME signed messages using OpenSSL's PKC

CVE advisoryCRITICAL

CVE-2026-44815

Windows DHCP Client Stack Buffer Overflow Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical stack-based buffer overflow vulnerability in the Windows DHCP Client enables unauthorized network attackers to execute code. This could compromise affected systems, impacting data confidentiality, integrity, and availability. Understanding this threat is vital for assessing environmental risks.

CVE advisoryCRITICAL

CVE-2026-38615

DedeCMS V5.7.118 Command Execution in file_manage_control.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command execution vulnerability exists in DedeCMS's file management functionality, potentially allowing unauthenticated network access to execute arbitrary commands on affected systems. This could lead to a complete system compromise, impacting data integrity and availability, making it crucial to identify a

CVE advisoryCRITICAL

CVE-2026-34182

OpenSSL CMS AuthEnvelopedData Validation Bypass and Key Equivalence Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in cryptographic message processing may allow attackers to bypass integrity checks or gain key-equivalent functionality. This issue affects how authenticated enveloped data containers are validated, potentially enabling unauthorized access to encryption keys or modification of messages. The FIPS modules

CVE advisoryCRITICAL

CVE-2026-26142

Nuance PowerScribe Network Code Execution via Untrusted Data Deserialization.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Nuance PowerScribe allows unauthorized remote code execution over a network due to untrusted data deserialization. If reachable, this could compromise system integrity and data. Understanding if your organization uses this technology and its network exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-8025

CBS Platform SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in CBS Platform. Attackers can manipulate database commands, potentially leading to unauthorized access or data modification. This issue is particularly concerning as the platform is no longer supported by the vendor, implying a lack of security updates. The primary concern

CVE advisoryKnown Exploit

CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability in Fortinet FortiSandbox may allow an unauthenticated attacker to execute unauthorized commands. This could impact the functionality and security of network security devices if reachable via specially crafted HTTP requests.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-10523

Ivanti Sentry Authentication Bypass Enables Full Administrative Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in Ivanti Sentry could allow an unauthenticated remote attacker to create arbitrary administrative accounts and gain full administrative access. This issue is relevant if Ivanti Sentry is used and accessible.

CVE advisoryKnown Exploit

CVE-2026-10520

Ivanti Sentry OS Command Injection Leads to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability in Ivanti Sentry could allow an unauthenticated remote attacker to execute code at the root level. This issue is critical because Ivanti Sentry is often internet-facing, potentially exposing organizations to significant compromise.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-7486

Netcad E-İmar SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An SQL injection vulnerability in Netcad E-İmar could allow attackers to manipulate database commands, potentially leading to unauthorized access or modification of data. This issue affects E-İmar software, and given its typical use in public-facing municipal applications, it is important to assess potential exposure a

CVE advisoryCRITICAL

CVE-2026-46325

Linux Kernel RDMA iova-to-va Conversion Flaw

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA subsystem could cause incorrect memory conversions when handling memory regions with non-standard page sizes. This could lead to system instability if reachable. The issue impacts the integrity of system memory mapping during RDMA operations.A vulnerability in the Linux kernel

CVE advisoryCRITICAL

CVE-2017-20251

WordPress Insert PHP Plugin Unauthenticated PHP Code Injection via REST API

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A PHP code injection vulnerability in a WordPress plugin allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API, potentially leading to unauthorized access or control of web environments.A PHP code injection vulnerability in the WordPress Insert P

CVE advisoryCRITICAL

CVE-2026-41031

Vinna Process Monitor Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Stored Cross-Site Scripting vulnerability exists in Vinna Process Monitor that allows an authenticated attacker to inject malicious JavaScript. This could potentially lead to the theft of administrative access tokens and session credentials. The relevance and exposure of this vulnerability within the environment need

CVE advisoryCRITICAL

CVE-2026-10731

SQL Injection in Two-Factor Authentication Allows Unauthenticated Database Access.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical SQL injection vulnerability exists in the two-factor authentication code parameter, allowing unauthenticated attackers to execute arbitrary SQL queries. This could lead to database enumeration, unauthorized creation of privileged users, or data modification.

CVE advisoryCRITICAL

CVE-2025-10263

Arm Processors Unauthorized Resource Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Certain Arm processor designs have a vulnerability allowing unauthorized writes to resources owned by a higher exception level. This could lead to system integrity and confidentiality compromises if reached. It's important to identify if affected Arm technologies are deployed within your environment to understand poten

CVE advisoryCRITICAL

CVE-2009-10007

Catalyst Plugin Authentication Session Fixation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A session fixation vulnerability exists in a Perl authentication plugin. Attackers could impersonate users by obtaining a session ID before authentication, as the plugin does not change the session ID after a user logs in. This impacts applications handling user sessions.

CVE advisoryCRITICAL

CVE-2026-9698

Perl DBI Buffer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A buffer overflow vulnerability exists in DBI for Perl, allowing attackers to trigger it by influencing error messages. This could lead to application instability or compromise. Technical readers should confirm relevance and exposure, while leaders should understand the potential impact on application integrity.

CVE advisoryCRITICAL

CVE-2026-5067

Zephyr HTTP Server WebSocket Upgrade Memory Corruption

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A memory corruption flaw exists in Zephyr's HTTP server when handling WebSocket upgrades. A remote, unauthenticated attacker can exploit this by sending a crafted header, potentially causing a denial-of-service or enabling code execution. This is relevant when the WebSocket feature is enabled.

CVE advisoryCRITICAL

CVE-2026-44748

SAP NetWeaver ABAP XML Tampering Leading to Unauthorized Access and Disruption.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authenticated attacker with normal privileges in SAP NetWeaver Application Server ABAP and ABAP Platform can send modified signed XML documents to the verifier, potentially leading to unauthorized access to sensitive user data and system disruption. This vulnerability poses a high risk to confidentiality, integrity,

CVE advisoryCRITICAL

CVE-2026-40128

SAP NetWeaver Java Web Container Path Traversal Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit a path traversal vulnerability in SAP NetWeaver Application Server Java's Web Container by crafting a malicious HTTP logon request that manipulates file inclusion parameters. This could allow them to view or modify sensitive information or render parts of the local system unavail

CVE advisoryCRITICAL

CVE-2026-27671

SAP Kernel RFC Protocol Validation Memory Corruption Leads to High Impact

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the SAP Kernel's RFC protocol validation allows unauthenticated attackers to corrupt memory via crafted requests, potentially impacting application confidentiality, integrity, and availability. The primary concern is determining the reachability and relevance of these SAP components within t

CVE advisoryCRITICAL

CVE-2026-11659

Google Chrome Linux Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Google Chrome on Linux allows a remote attacker to potentially escape the browser's sandbox via a crafted HTML page, which could lead to broader system compromise. This vulnerability is reachable through user interaction with malicious websites.

CVE advisoryCRITICAL

CVE-2026-11654

Chrome CameraCapture Use After Free Sandbox Escape.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on Mac could allow a remote attacker to escape the browser sandbox via a crafted HTML page, potentially leading to broader system access. The primary concern is to confirm if vulnerable Chrome versions are in use within the organization.

CVE advisoryCRITICAL

CVE-2026-11651

Chrome Network Use-After-Free Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome may allow a remote attacker to execute arbitrary code. Attackers could exploit this by tricking a user into visiting a crafted HTML page, potentially impacting the security of web interactions. Confirmation of affected Chrome installations is the primary action needed.

CVE advisoryCRITICAL

CVE-2026-11638

Chrome Sandbox Escape Vulnerability in Printing

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Google Chrome's printing component, potentially allowing a remote attacker to escape the browser's sandbox through a crafted HTML page. This critical flaw requires user interaction to exploit, raising concerns about relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-11634

Google Chrome Sandbox Escape via Use After Free in Gamepad

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Gamepad component allows a remote attacker to potentially escape the browser sandbox via a crafted HTML page. This impacts confidentiality, integrity, and availability by enabling unauthorized system access.