NVD disclosure day

Published threat advisories for June 16, 2026

CVE advisoryCRITICAL

CVE-2026-48777

FileBrowser Quantum Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability exists in FileBrowser Quantum, a self-hosted file manager. This flaw allows an attacker with a public share link that permits modifications to move, copy, or rename files outside the intended shared directory. The issue stems from improper path handling before sanitization, enabling unaut

CVE advisoryCRITICAL

CVE-2026-22313

Device Management REST API OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in a device's web server REST API, allowing authenticated attackers to execute arbitrary commands with administrative privileges. While this flaw could lead to a complete system compromise, it is currently classified as unlikely to be externally exploitable as it resides on a management

CVE advisoryCRITICAL

CVE-2026-0126

Android WC-Radio Out of Bounds Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in WC-Radio within the Android operating system, allowing for remote code execution via an out-of-bounds write without user interaction. While network-exploitable, this component is typically used internally, making its direct internet exposure less common.

CVE advisoryCRITICAL

CVE-2026-53776

Perry JWT Validation Bypass Allows Indefinite Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A JWT validation vulnerability in Perry allows remote attackers to bypass token expiration, potentially granting indefinite authenticated access using previously issued tokens. This could circumvent session invalidation mechanisms like logouts or revocations, posing a significant risk to systems relying on this JWT ver

CVE advisoryCRITICAL

CVE-2025-13036

FactoryTalk Historian Site Edition Authentication Bypass

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authentication bypass exists in FactoryTalk Historian Site Edition, allowing an attacker to obtain a valid token by sending continuous requests to the login endpoint. The primary concern is understanding if this affects your systems, as FactoryTalk Historian Site Edition is typically isolated within internal network

CVE advisoryCRITICAL

CVE-2026-12316

Mitigation Bypass in Mozilla DOM Security Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the DOM security component can allow attackers to bypass security measures in web browsers and email clients. This could lead to unauthorized access and modification of data if a user interacts with malicious content. Affected applications have been updated to address this issue.

CVE advisoryCRITICAL

CVE-2026-12315

Firefox Thunderbird Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the DOM security component of certain widely used web and email software, allowing for a mitigation bypass. This could lead to significant compromise of user data and system integrity if exploited, particularly given its high severity and the potential for unauthorized access and exec

CVE advisoryCRITICAL

CVE-2026-12304

Same-Origin Policy Bypass Affects Mozilla Networking Cookies

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A same-origin policy bypass vulnerability exists in the Networking: Cookies component of certain web browser and email client software. If reachable, this could allow unauthorized access to sensitive information or manipulation of web content by a malicious website. This could occur when a user interacts with compromis

CVE advisoryCRITICAL

CVE-2026-12297

Firefox and Thunderbird Networking Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the networking component of certain applications may allow an attacker to escape the program's sandbox. This could potentially lead to the compromise of a user's system if a user interacts with malicious content. Uncertainty remains regarding which specific products and versions are affected

CVE advisoryCRITICAL

CVE-2026-12296

Sandbox Escape Vulnerability in Mozilla Security Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the security component that isolates processes within browsers and email clients. This flaw could allow an attacker to escape this isolated environment, potentially leading to system compromise if users interact with malicious content, impacting data confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-12295

Firefox DOM Navigation Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in the DOM: Navigation component, which could allow attackers to compromise user systems if they interact with malicious web content. This issue affects Firefox and Thunderbird clients, and while exploitation requires user interaction, it poses a risk to sensitive informat

CVE advisoryCRITICAL

CVE-2026-12294

Firefox and Thunderbird DOM Workers Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A sandbox escape vulnerability exists in the DOM: Workers component of affected browser and email client software, allowing potential breakout from restricted environments. While user interaction with malicious content is required, this could impact system integrity and availability if exploited.

CVE advisoryCRITICAL

CVE-2026-12293

Firefox and Thunderbird Use-After-Free in Graphics WebGPU Component.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in the Graphics: WebGPU component of Firefox and Thunderbird could allow an attacker to execute arbitrary code or cause a denial of service. This could occur when processing web content, potentially impacting the integrity and availability of the affected application.

CVE advisoryCRITICAL

CVE-2026-40750

Kids Online Store Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unrestricted file upload vulnerability exists in the Kids Online Store, enabling authenticated users to upload web shells to the server. This could allow for arbitrary code execution and potentially a full system compromise. The issue arises from inadequate restrictions on file types that can be uploaded, making the

CVE advisoryCRITICAL

CVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress Plugin Versions 4.5.5 and Earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the GEO my WordPress plugin. This could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized access or manipulation of database information, affecting service availability.

CVE advisoryCRITICAL

CVE-2026-49774

RD Station Code Injection Vulnerability Allows Remote Code Inclusion.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical code injection vulnerability in RD Station allows remote code inclusion. This means an attacker could potentially execute arbitrary code on a system, leading to unauthorized access or compromise. It's important to confirm if this technology is in use and assess any potential exposure.

CVE advisoryCRITICAL

CVE-2026-49772

StellarWP The Events Calendar Blind SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Blind SQL Injection vulnerability in The Events Calendar plugin may allow an attacker to inject malicious database commands and potentially access sensitive information. This issue is reachable via network requests and affects the underlying database. Organizations should confirm if this plugin is in use and assess p

CVE advisoryCRITICAL

CVE-2026-39574

InPost Gallery Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the InPost Gallery plugin, allowing attackers to execute arbitrary SQL commands and potentially access sensitive data. This is a critical issue for websites using the plugin, as it could lead to unauthorized data access or service disruption. Confirmation of its