NVD disclosure day

Published threat advisories for June 11, 2026

CVE advisoryCRITICAL

CVE-2026-45060

ClipBucket Blind SQL Injection Vulnerability in actions/progress_video.php

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

ClipBucket, an open-source video sharing platform, has a blind SQL injection vulnerability in its `actions/progress_video.php` endpoint. This allows unauthenticated users to execute SQL queries, potentially leading to the exfiltration of sensitive data.

CVE advisoryCRITICAL

CVE-2026-42846

ClipBucket Remote Play Arbitrary Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ClipBucket's Remote Play feature allows arbitrary command execution via a specially crafted URL. This impacts organizations using ClipBucket v5 for video sharing by potentially enabling command execution on their servers through unauthenticated access.

CVE advisoryCRITICAL

CVE-2026-42647

JoomSport Blind SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in JoomSport allows attackers to access sensitive data by sending specially crafted network requests. This could impact the confidentiality and integrity of data managed by the software. Confirm if JoomSport is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-39494

Product Filter by WBW SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in the Product Filter by WBW plugin allows attackers to potentially access sensitive data. If this plugin is in use and reachable, it could lead to data exposure or unauthorized actions. Confirming its presence and exposure is important for risk management.

CVE advisoryCRITICAL

CVE-2026-12027

Chrome Headless Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Google Chrome's Headless implementation could allow a compromised renderer process to escape the browser's sandbox. This may enable an attacker to affect system data and service behavior via a crafted HTML page. The relevance depends on whether the Headless component is used and exposed.

CVE advisoryCRITICAL

CVE-2026-41005

Cloud Foundry UAA SAML Authentication Bypass via Unsigned Encrypted Assertions

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cloud Foundry UAA incorrectly accepts SAML assertions that are encrypted but not signed, potentially allowing authentication bypass. This means an attacker could send forged assertions, leading to unauthorized access, if the affected SAML flows are used and `wantAssertionSigned` is set to false.

CVE advisoryCRITICAL

CVE-2026-49973

Hermes WebUI Improper Access Control Allows Password Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper access control vulnerability in Hermes WebUI allows unauthenticated remote attackers to hijack initial setup by setting an arbitrary password. This can lead to unauthorized session access and lockout of legitimate operators. The vulnerability's relevance and exposure to business operations should be confirm

CVE advisoryCRITICAL

CVE-2026-47174

Duck Site Deploy Workflow Bypass.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Duck Site's deployment workflow that could allow an attacker to deploy unmerged code directly to production. This occurs if a pull request meets conditions that trigger the deploy workflow, which runs with elevated permissions. The primary concern is confirming the relevance and expos

CVE advisoryCRITICAL

CVE-2026-47172

Quest Bot Privileged Workflow Allows Malicious Container Deployment

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Quest Bot's deployment workflow that could allow an attacker to deploy malicious code in a production environment, leading to bot compromise. The issue occurs if an attacker can submit a pull request from a specific branch, potentially enabling the build and deployment of attacker-controlled c

CVE advisoryCRITICAL

CVE-2026-45177

Idira Secrets Manager SaaS Edge Improper Access Control Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Improper access control in Idira Secrets Manager SaaS Edge may allow unauthenticated attackers to obtain access tokens by manipulating validation mechanisms. While the exact impact and affected data are uncertain, this vulnerability could lead to unauthorized access to sensitive secrets management tokens. Readers shoul

CVE advisoryCRITICAL

CVE-2026-49261

MariaDB Command Execution Vulnerability When wsrep_notify_cmd is Enabled.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

MariaDB server versions may allow shell command execution if the `wsrep_notify_cmd` configuration is enabled. This occurs when commands are embedded in the name of a joining node, potentially leading to unauthorized command execution. Confirming the use of this software and configuration is important for assessing pote

CVE advisoryCRITICAL

CVE-2026-9648

Crypton-x509-validation NameConstraints Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The crypton-x509-validation Haskell library has a flaw that could allow TLS clients to accept certificates for domains outside their permitted scope. If reachable, an attacker could impersonate domains, potentially impacting digital trust and identity. It is important to determine if this library is in use and assess i

CVE advisoryCRITICAL

CVE-2026-11839

Rotaban Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Rotaban allows uploading dangerous files to a web server, potentially enabling system control. This affects Rotaban versions before V2026.06.003 and requires authenticated, low-privilege access. The impact depends on the application's deployment and network exposure, necessitating verificati

CVE advisoryCRITICAL

CVE-2026-38581

Damasac thaipalliative_lte SQL Injection Vulnerability in ezform.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the `thaipalliative_lte` web application, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or deletion of sensitive data stored in the database. Confirming the presence and exposure of this technolo

CVE advisoryCRITICAL

CVE-2026-7852

LimRAD NAC Unrestricted File Upload Vulnerability Allows Remote Code Inclusion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unrestricted file upload vulnerability in LimRAD NAC allows remote code inclusion, potentially enabling unauthorized access and control. This issue poses a risk if the system is reachable, as it could lead to compromised system integrity and arbitrary command execution. Leaders should focus on identifying affected i

CVE advisoryCRITICAL

CVE-2026-11561

Apinizer Expression Language Injection Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An expression language injection vulnerability in Apinizer could permit code injection. If reachable, this flaw could enable an attacker to execute arbitrary code on the affected system. This threat is relevant to organizations using Apinizer, potentially impacting their systems if exploitation occurs.

CVE advisoryCRITICAL

CVE-2026-41699

Spring for GraphQL Unsafe Deserialization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Spring for GraphQL applications may allow remote code execution through unsafe deserialization when processing paginated GraphQL queries. An attacker could exploit this by sending a crafted request, potentially leading to compromised applications if specific conditions are met.

CVE advisoryKnown Exploit

CVE-2026-35273

Oracle PeopleSoft Updates Environment Management Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers with network access to take control of the system via HTTP. This could lead to the compromise of all data and functionalities. Confirmation of affected environments and potential exposure is necessary.

• CISA KEV