NVD disclosure day

Published threat advisories for June 12, 2026

CVE advisoryCRITICAL

CVE-2026-53609

ApostropheCMS `__proto__` Prototype Pollution Leading to Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated editor can exploit a flaw in ApostropheCMS, a Node.js content management system, to bypass authorization checks. This prototype pollution vulnerability could allow unauthenticated users to access sensitive content or features for the duration of the application process, impacting internet-facing conten

CVE advisoryCRITICAL

CVE-2026-53519

Nezha Monitoring Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Nezha Monitoring allows unauthenticated access to sensitive configuration files by exploiting improper URL handling. This could lead to the disclosure of private system details if the monitoring tool is reachable. This issue has been patched in version 2.0.13.

CVE advisoryCRITICAL

CVE-2026-46716

Nezha Monitoring Cross-Tenant Command Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Nezha Monitoring, a server management tool, contains a critical vulnerability allowing a user with RoleMember access to execute arbitrary commands across all servers within the system, including those of other tenants. This could lead to widespread system compromise and operational disruption. This issue is resolved in

CVE advisoryCRITICAL

CVE-2026-41157

WebGPU Out-of-Bounds Write in GPU Driver Leads to Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in GPU drivers that can be triggered by malicious web content, leading to memory corruption and potential browser or GPU process crashes. This issue stems from an integer overflow allowing out-of-bounds writes, highlighting a risk in how complex web content is handled.

CVE advisoryCRITICAL

CVE-2026-44990

sanitize-html Bypass in ApostropheCMS Leads to Stored Cross-Site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the `sanitize-html` library, used by ApostropheCMS, can allow attacker-controlled content within an `xmp` element to be rendered as live HTML or JavaScript. This bypasses intended security, potentially leading to stored cross-site scripting if unsanitized user input is displayed to others. The issue

CVE advisoryCRITICAL

CVE-2026-53407

Zoom Workplace Android and iOS Improper Authorization Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An improper authorization vulnerability in Zoom Workplace's custom URL scheme handler for Android and iOS could allow an unauthenticated user to escalate privileges via network access. This may lead to unauthorized control over device functions, potentially impacting user data.

CVE advisoryCRITICAL

CVE-2026-50101

Naxclow Device Relay Credential Exposure Allows Persistent Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Naxclow devices allows attackers to obtain a persistent relay credential. This credential, which is re-issued on each boot and never rotates, enables long-term impersonation or interception of device communications, even after resets. Organizations should confirm if they use affected Naxclow devices

CVE advisoryKnown Exploit

CVE-2026-48558

SimpleHelp OIDC Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authentication bypass vulnerability in SimpleHelp's OIDC flow allows unauthenticated attackers to forge identity tokens, gaining unauthorized technician access and potentially bypassing multi-factor authentication. This issue requires immediate attention to confirm relevance and exposure within your environm

• CISA KEV

CVE advisoryHIGH

CVE-2026-50091

Aqara Home Android SDK Uses Hard-Coded Cryptographic Keys

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Aqara Home Android applications and white-label clients using the same SDK contain hard-coded cryptographic keys, which could allow attackers to access or modify sensitive data. This vulnerability is critical and requires verifying if the affected technology is relevant and exposed within the environment.

CVE advisoryCRITICAL

CVE-2026-50086

Aqara IAM/SSO Gateway Unauthenticated AES Oracle Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Aqara IAM/SSO gateway has a vulnerability that allows unauthenticated parties to perform cryptographic operations, potentially leading to unauthorized access. This is because it exposes AES encryption/decryption functions without requiring authentication. Organizations should confirm if this gateway is relevant to

CVE advisoryMEDIUM

CVE-2026-50084

Aqara Cloud API Missing Authorization Allows Account Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authorization vulnerability exists in the Aqara Cloud Production API, where a valid developer token can grant access to any account. This "missing authorization" flaw (CWE-862) could allow unauthorized account access and, when combined with other vulnerabilities, potentially lead to a complete remote takeove

CVE advisoryCRITICAL

CVE-2026-50083

Aqara Gateway Hardcoded OAuth Credentials Lead to Unauthenticated Remote Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A hard-coded OAuth client credential in the Aqara IAM/SSO Gateway could allow unauthenticated remote takeover of devices, especially when combined with other vulnerabilities. This critical flaw exposes a potential entry point for attackers.

CVE advisoryCRITICAL

CVE-2026-47691

Netty DNS Cache Poisoning Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Netty, a network application framework, contains a DNS cache poisoning vulnerability where an attacker controlling a subdomain's name server can manipulate DNS records for parent domains. This could lead to future DNS resolutions being directed to attacker-controlled infrastructure.

CVE advisoryCRITICAL

CVE-2026-6853

Pause+ Mobile App Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper restriction of excessive authentication attempts vulnerability in the Pause+ Mobile App allows for authentication bypass. If reachable, this could lead to unauthorized access to the application's functions and potentially sensitive information. It is important to determine if this mobile app is deployed and

CVE advisoryCRITICAL

CVE-2026-53787

Amasty Order Attributes Unauthenticated File Upload Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated arbitrary file upload vulnerability exists in Amasty Order Attributes for Magento 2, allowing attackers to place any file type on the server. This could lead to remote code execution if the media directory allows PHP execution, or enable malware hosting and cross-site scripting.

CVE advisoryCRITICAL

CVE-2026-47210

vm2 Sandbox Escape Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Node.js vm2 library allows arbitrary code execution in the host process when untrusted code is executed with async support. This sandbox escape occurs when a Promise interacts with certain JavaScript APIs, breaking the security boundary. Applications using the affected vm2 versions could

CVE advisoryCRITICAL

CVE-2026-47208

VM2 Sandbox Breakout Vulnerability Allows Host Command Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 Node.js sandbox library has a critical vulnerability allowing code to escape its sandbox and execute arbitrary commands on the host system. This could impact system data and service behavior if an attacker can reach and exploit it, making it important to confirm if this technology is in use and exposed within y

CVE advisoryCRITICAL

CVE-2026-47140

vm2 Node.js Sandbox Allows Host Process Execution via Weak Built-in Denylist

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 Node.js sandboxing library allowed sandboxed code to execute commands on the host system by bypassing restrictions on certain Node.js built-ins. This could lead to compromise of the underlying application or infrastructure. The issue has been patched in version 3.11.4.

CVE advisoryCRITICAL

CVE-2026-47137

vm2 Sandbox Bypass Leads to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 Node.js sandbox allows bypassing security checks, potentially enabling code execution. This issue arises from a flawed strict equality check that can be circumvented, leading to unintended configurations. Readers should confirm if their Node.js applications use vm2 and are affected by this by

CVE advisoryCRITICAL

CVE-2026-47131

vm2 Sandbox Escape Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Node.js vm2 sandbox library allows attackers to escape the sandbox and execute arbitrary code by manipulating JavaScript's `Buffer` object and Node.js's error handling. This could impact system integrity if the library is used in deployed applications.

CVE advisoryCRITICAL

CVE-2026-45674

Netty DNS Validation Flaw Allows Spoofed Responses

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Netty's DNS resolution could allow attackers to intercept network traffic. This issue arises from insufficient validation of CNAME records in DNS responses, potentially enabling the redirection of communication to malicious servers. Given Netty's role as a network application framework, this flaw war

CVE advisoryCRITICAL

CVE-2026-10557

Yarbo Robot Fleet Credentials Leakness

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Yarbo mobile applications contain hard-coded credentials that provide access to cloud MQTT brokers. These brokers carry real-time telemetry for the global Yarbo robot fleet, and the credentials allow unauthorized subscription to telemetry and publishing of commands to any robot. This vulnerability is critical becau

CVE advisoryCRITICAL

CVE-2026-11849

iRM-IEI Remote Management Hardcoded Credentials Grant Administrative Database Access.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The iRM-IEI Remote Management system contains hard-coded credentials, allowing unauthenticated remote attackers to gain administrative privileges on its database. This vulnerability could expose sensitive data and compromise system integrity. Identification of affected systems and their reachability is crucial.

CVE advisoryHIGH

CVE-2026-50633

Apache CXF JCA JNDI Injection Vulnerability Allows Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A JNDI Injection vulnerability in Apache CXF's JCA integration module could allow for code execution. This is a critical vulnerability that could be exploited if an attacker can manipulate JCA deployment descriptors or runtime parameters. The main concern is confirming relevance and exposure to this vulnerability.

CVE advisoryCRITICAL

CVE-2026-50628

Apache CXF OAuth Request Filter Logic Error

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A logic error in Apache CXF's OAuthRequestFilter could allow unauthorized access by incorrectly validating IP addresses when a security feature is enabled. This flaw may permit requests from any IP address while blocking legitimate ones, potentially leading to data exposure and service compromise.

CVE advisoryCRITICAL

CVE-2026-50627

Apache CXF JWT Audience Validation Token Confusion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Apache CXF's JwtAccessTokenValidator may allow a JWT intended for one resource server to be accepted by another, enabling token confusion attacks. This could potentially lead to unauthorized access or actions if the affected component is network-reachable. Further assessment is needed to confirm rele

CVE advisoryCRITICAL

CVE-2026-49875

Apache CXF XML External Entity Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Apache CXF allows for external entity resolution, which could lead to sensitive information disclosure or denial of service. This issue arises from how certain classes construct a SAXParserFactory without proper hardening. Given Apache CXF's widespread use in building web services and APIs, systems u

CVE advisoryCRITICAL

CVE-2026-47370

UniFi OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper input validation vulnerability in UniFi OS devices allows a low-privilege network attacker to execute commands, potentially compromising the device. This issue is critical due to the common use of UniFi OS for network management and control, which may expose these devices to reachability.

CVE advisoryCRITICAL

CVE-2026-47369

UniFi OS Privilege Escalation via Improper Input Validation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An improper input validation vulnerability in certain UniFi OS devices can be exploited by a low-privilege attacker with network access to escalate privileges, potentially leading to unauthorized control and data access. The relevance and exposure of affected devices require confirmation.

CVE advisoryCRITICAL

CVE-2026-47367

UID Enterprise Agent Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An Improper Input Validation vulnerability in the UID Enterprise Agent could allow a low-privilege, network-accessible attacker to execute commands on a host device. This is a concern because unauthorized command execution can impact system integrity and availability.

CVE advisoryCRITICAL

CVE-2026-47365

WordPress Toolkit Argument Injection in cPanel & WHM

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An argument injection vulnerability in WordPress Toolkit, used within cPanel & WHM, allows authenticated users to bypass authorization and execute arbitrary commands as other accounts. This could impact system integrity and data security if the affected technology is reachable and relevant.