NVD disclosure day

Published threat advisories for June 17, 2026

CVE advisoryCRITICAL

CVE-2026-55743

OpenHuman Desktop Agent Command Allowlist Bypass Leads to Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the OpenHuman desktop agent allows bypassing its command allowlist to execute arbitrary OS commands with user privileges. This can occur when the agent processes malicious content, leading to potential remote code execution, data exfiltration, and system compromise. Confirmation of the agent's presen

CVE advisoryCRITICAL

CVE-2026-54812

Motors Plugin SQL Injection Affects Publicly Accessible Sites.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the StylemixThemes Motors plugin, allowing unauthenticated attackers to potentially extract sensitive database information or cause service disruptions. Since the plugin is designed for public-facing automotive dealership and classified listing websites, it is likely acc

CVE advisoryCRITICAL

CVE-2026-47103

Python StateMachine SCXML Injection RCE

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Python StateMachine library allows remote code execution when processing malicious SCXML documents. Attackers can exploit this by supplying crafted documents that cause arbitrary code to run within the application's process. The reachability of this vulnerability depends on how the library is imp

CVE advisoryCRITICAL

CVE-2026-42530

NGINX Open Source HTTP/3 Use-after-Free Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in NGINX Open Source's HTTP/3 QUIC module, potentially allowing unauthenticated remote attackers to cause a denial-of-service or execute code. This occurs through a specially crafted HTTP/3 session that triggers a use-after-free condition, leading to a worker process restart or, under sp

CVE advisoryCRITICAL

CVE-2026-42055

NGINX HTTP/2 and gRPC Heap Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap-based buffer overflow in NGINX proxy modules may allow an attacker to cause a service restart or execute code under specific, complex conditions. This vulnerability affects NGINX when using certain proxy configurations for HTTP/2 or gRPC traffic with large client headers. Understanding the relevance and exposure

CVE advisoryCRITICAL

CVE-2026-54815

Cargo Shipping Location for WooCommerce Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in the Cargo Shipping Location for WooCommerce plugin allows attackers to access sensitive database information. The vulnerability is reachable via the network and can be exploited by unauthenticated attackers, potentially leading to unauthorized data exposure on e-commerce sites.

CVE advisoryCRITICAL

CVE-2026-54809

GIFT4U Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in the GIFT4U WordPress plugin allows attackers to inject malicious SQL commands. If reachable, this could lead to unauthorized access to or manipulation of sensitive data. Confirming the use of this plugin and assessing potential data exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-54808

WP Travel Gutenberg Blocks Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in WP Travel Gutenberg Blocks, allowing attackers to potentially access and modify sensitive database information. This issue is relevant to public-facing WordPress sites using the plugin, as it could lead to unauthorized data exposure or tampering without requiring special access o

CVE advisoryCRITICAL

CVE-2026-49108

Moderno Theme Unauthenticated PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Moderno web theme. This flaw allows remote attackers to execute arbitrary code, potentially leading to a full system compromise if the theme is reachable. Understanding the presence and reachability of this theme is important for assessing risk.

CVE advisoryCRITICAL

CVE-2025-69127

Unauthenticated PHP Object Injection in Plumbing <= 1.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in Plumbing software, potentially allowing remote attackers to inject malicious PHP objects. This could lead to arbitrary code execution and a complete compromise of the affected server. It is important to confirm if Plumbing software is in use and assess its

CVE advisoryCRITICAL

CVE-2025-69111

Reisen Theme PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP object injection vulnerability exists in the Reisen theme, allowing unauthenticated attackers to potentially execute code. This affects external-facing web applications, posing a significant risk of system compromise if reachable. Readers should confirm relevance and understand potential exposure.

CVE advisoryCRITICAL

CVE-2025-60236

EMV Creatify Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in the EMV Creatify WordPress theme allows for object injection. If reachable, an attacker could exploit this by sending specially crafted data, potentially leading to the execution of malicious code or system compromise. Readers should care because this is a critical flaw in an internet

CVE advisoryCRITICAL

CVE-2025-60231

The Hospital nrghospital PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in The Hospital WordPress theme allows object injection, potentially enabling attackers to compromise system integrity. This issue affects the theme's handling of untrusted data, making it a target for malicious code injection if reachable.

CVE advisoryCRITICAL

CVE-2025-60230

The Barber Shop Deserialization Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization of untrusted data vulnerability in The Barber Shop theme allows object injection, potentially enabling unauthorized code execution on affected systems. This critical issue requires immediate attention due to its network-accessible nature and potential to compromise system integrity and availability.

CVE advisoryCRITICAL

CVE-2025-60229

Themeton Lagom Object Injection Vulnerability in WordPress Theme

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization flaw in the Themeton Lagom WordPress theme allows attackers to inject malicious objects. If reachable, this could enable arbitrary code execution, potentially impacting system integrity and availability. Readers should care because this critical vulnerability can be exploited remotely without authenti

CVE advisoryCRITICAL

CVE-2025-59554

SQL Injection in Advanced Ads – Tracking before 3.0.7

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Advanced Ads – Tracking WordPress plugin, potentially allowing attackers to access or modify database information. This issue requires attention to understand its relevance and potential impact on your systems.

CVE advisoryCRITICAL

CVE-2026-54811

WP eMember SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a WordPress membership plugin that could allow attackers to access or manipulate sensitive database information. The concern is whether this plugin is used in your environment, as it could expose member and access control data.

CVE advisoryCRITICAL

CVE-2026-54807

WooCommerce Registration Form Unauthenticated Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in a WooCommerce registration form plugin, allowing unauthenticated attackers to gain elevated privileges. This issue impacts public-facing websites and could lead to unauthorized administrative access if the plugin is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-54806

PHP Object Injection in WP Activity Log

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the WP Activity Log plugin, potentially allowing attackers to compromise affected websites by injecting and executing arbitrary PHP objects. This could lead to unauthorized control, data manipulation, or service disruption.

CVE advisoryCRITICAL

CVE-2026-54803

Subscriber Privilege Escalation in SMS Alert Order Notifications

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical privilege escalation vulnerability affects SMS Alert Order Notifications, potentially allowing unauthorized users to gain higher system privileges without authentication. This issue presents a significant security risk if the affected software is accessible over the network. Confirming the presence and usage

CVE advisoryCRITICAL

CVE-2026-54194

Fusion Builder PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A PHP Object Injection vulnerability in Fusion Builder can allow attackers to execute arbitrary code remotely, potentially compromising affected systems. The issue does not require authentication or user interaction for exploitation. It is uncertain if this component is in use or exposed in your environment.

CVE advisoryCRITICAL

CVE-2026-54187

JetEngine SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated SQL injection vulnerability exists in the JetEngine WordPress plugin. Attackers can exploit this flaw remotely to inject malicious SQL commands, potentially leading to unauthorized access and manipulation of sensitive database information. This poses a risk to data integrity and confidentiali

CVE advisoryCRITICAL

CVE-2026-54186

JobSearch Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in JobSearch, allowing attackers to execute arbitrary SQL commands on the database. This could lead to unauthorized access to or modification of sensitive data if the affected component is reachable online. Understanding if this software is in use and its exposure i

CVE advisoryCRITICAL

CVE-2026-52706

JetEngine Unauthenticated PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in JetEngine that could allow unauthenticated attackers to inject PHP code over the network. If reachable, this could lead to arbitrary code execution on the server, impacting website data and integrity. Confirming if JetEngine is in use and exposed is essential to assess and address pot

CVE advisoryCRITICAL

CVE-2026-52705

SigmaForms Pro Arbitrary File Upload Vulnerability in AI Generated Forms <= 1.4.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

This critical vulnerability allows unauthenticated users to upload arbitrary files using SigmaForms Pro's AI-generated forms, potentially leading to severe security breaches. If this technology is relevant and reachable in our environment, it could impact website integrity and service availability by enabling the execu

CVE advisoryCRITICAL

CVE-2026-50203

SFTP Provider Path Traversal Allows Remote File Write

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in the SFTP provider allows a malicious or compromised SFTP server to write files outside the designated local directory. This could affect any deployment downloading directories from untrusted SFTP servers, as no Airflow account is required to exploit it.

CVE advisoryCRITICAL

CVE-2026-49767

wpForo Forum Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authentication vulnerability exists in the wpForo Forum plugin, allowing unauthenticated access to forum data and functions. This could lead to unauthorized control and compromise of user information. Assess plugin usage and network exposure.

CVE advisoryCRITICAL

CVE-2026-49107

Thrive Apprentice Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated PHP Object Injection vulnerability exists in Thrive Apprentice, a WordPress plugin, enabling attackers to potentially compromise systems without authentication. This vulnerability is reachable via the network and could lead to severe data compromise if exploited. Action is needed to determine

CVE advisoryCRITICAL

CVE-2026-49084

JetEngine Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in JetEngine, potentially allowing attackers to access or manipulate sensitive database information. This issue is classified as external and likely reachable from the internet, posing a risk to data integrity and confidentiality. Confirming the presence and reachab

CVE advisoryCRITICAL

CVE-2026-49080

Unauthenticated SQL Injection in wpDataTables Plugin Versions <= 7.3.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the wpDataTables WordPress plugin, allowing unauthenticated attackers to potentially access sensitive database information. This issue is network-exposed and does not require user interaction for exploitation. The primary concern is confirming the plugin's presence and r

CVE advisoryCRITICAL

CVE-2026-49076

JetEngine Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the JetEngine plugin, potentially allowing attackers to access or manipulate data without authentication. This could lead to unauthorized data exposure or system compromise if the plugin is exposed to the network.

CVE advisoryCRITICAL

CVE-2026-49075

JetEngine PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP object injection vulnerability exists in JetEngine, a WordPress plugin. If reachable, an unauthenticated attacker could inject and execute arbitrary PHP code, potentially compromising system data and integrity. This vulnerability could allow remote code execution and impact website security.

CVE advisoryCRITICAL

CVE-2026-49058

LoginPress Pro Unauthenticated Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in LoginPress Pro that allows unauthenticated attackers to escalate their privileges. This means an attacker could gain higher access levels without needing to log in, potentially impacting user authentication processes. It is important to determine if this plugin is used and accessible

CVE advisoryCRITICAL

CVE-2026-48875

JetSmartFilters Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a widely used website filtering plugin, potentially allowing attackers to access or manipulate database information without logging in. This could impact data integrity and security on affected sites, necessitating confirmation of its presence and assessment of p

CVE advisoryCRITICAL

CVE-2026-48797

Backpropagate UI Unauthenticated Training Control Plane Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Backpropagate library's web UI, intended for fine-tuning large language models, can expose training controls without authentication when accessible over a network. An attacker could leverage this to upload datasets, manipulate models, and trigger denial-of-service conditions, impacting data and system availability.

CVE advisoryCRITICAL

CVE-2026-48781

Postiz Skool Integration JWT Vulnerability Allows Superadmin Impersonation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Postiz, an AI social media scheduling tool, allows an authenticated user to forge administrative credentials. This can lead to unauthorized full access to the application, including user data and the ability to post from impersonated social media channels. The issue is related to the handling of sign

CVE advisoryCRITICAL

CVE-2026-48745

Traccar Client Deep Link Hijacks GPS Tracking

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Traccar Client mobile app allows a crafted link to secretly hijack GPS tracking parameters and redirect telemetry to an attacker-controlled server. This happens when a user taps a malicious deep link, silently reconfiguring the app without confirmation, leading to continuous, real-time location t

CVE advisoryCRITICAL

CVE-2026-42380

AI Lab Theme Unauthenticated PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability has been identified in AI Lab, a critical issue that could allow an attacker to inject malicious objects. If reachable, this vulnerability may lead to unauthorized control, sensitive information disclosure, data modification, or service disruption. Confirming the pr

CVE advisoryCRITICAL

CVE-2026-40783

Blocksy Companion Pro Contributor RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical contributor remote code execution vulnerability exists in the Blocksy Companion Pro plugin, allowing for arbitrary code execution on the server. This affects websites built with the plugin, which are commonly exposed to the internet, potentially impacting data integrity and availability. Readers should care

CVE advisoryCRITICAL

CVE-2026-40749

Charity Zone Theme Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in Charity Zone themes, allowing low-privileged users to upload arbitrary files. If reachable, this could lead to code execution and unauthorized access to sensitive information. This impacts web applications using the affected theme.

CVE advisoryCRITICAL

CVE-2026-40748

Kids Gift Shop Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in the Kids Gift Shop theme, allowing authenticated subscribers to upload malicious files to the server. If reachable, this could lead to system compromise. Website owners should verify its presence and address it if in use.

CVE advisoryCRITICAL

CVE-2026-40747

Subscriber Arbitrary File Upload in Ecommerce Zone Theme

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in the Ecommerce Zone theme, potentially allowing authenticated subscribers to upload malicious files. If reachable, this could lead to system compromise and unauthorized code execution. Further assessment is needed to understand the specific business impact and rel

CVE advisoryCRITICAL

CVE-2026-40746

Restaurant Zone Theme Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in the Restaurant Zone theme. If reachable, an attacker with low-privileged access could upload malicious files, potentially leading to unauthorized code execution and system compromise. Confirming the use and exposure of this theme is crucial.

CVE advisoryCRITICAL

CVE-2026-40725

PHP Object Injection in WooCommerce Product Filters

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in WooCommerce Product Filters, potentially allowing attackers to execute arbitrary code. This could impact website data and functionality. Confirming relevance and exposure is advised for affected e-commerce platforms.

CVE advisoryCRITICAL

CVE-2026-39596

Blocksy Companion Pro SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Blocksy Companion Pro plugin that allows unauthenticated attackers to execute arbitrary SQL commands. If reachable, this could lead to unauthorized access to sensitive database information or service disruption. This issue is relevant because it affects a widely used

CVE advisoryCRITICAL

CVE-2026-39529

Elementra Theme PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Elementra WordPress theme. Attackers can exploit this by sending crafted data, potentially leading to arbitrary code execution and severe system compromise. Confirming the presence and exposure of this theme within your environment is crucial.

CVE advisoryCRITICAL

CVE-2026-32967

Apache DolphinScheduler Unauthorized Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An incorrect authorization flaw exists in Apache DolphinScheduler's experimental `/v2` interface. This vulnerability, if reachable, could allow unauthenticated users to gain unauthorized access and potentially modify data. This impacts workflow orchestration platforms and warrants attention to assess exposure and plan

CVE advisoryCRITICAL

CVE-2026-32966

Apache DolphinScheduler API Authorization Bypass Disclosure Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Apache DolphinScheduler due to a missing authorization check in its DataSource API. This allows unauthenticated users to disclose sensitive data source metadata, potentially impacting system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-28615

Telecomm Permissions Bypass Enables Unauthorized Calls

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A permissions bypass in telecommunication functions allows unauthorized phone calls and local privilege escalation without user interaction, posing a risk if reachable or relevant within the environment. The exact telecommunication functions impacted are not specified, leading to uncertainty regarding the scope and bus

CVE advisoryCRITICAL

CVE-2026-28587

Android MmsSmsProvider Missing Permission Check Leads to Information Disclosure.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Android's MmsSmsProvider, allowing sensitive local information disclosure due to a missing permission check. Exploitation requires no user interaction or special privileges, but the impact is limited to data accessible on the device. Confirming affected devices and assessing business

CVE advisoryCRITICAL

CVE-2026-28576

SQL Injection in Android Contacts Provider Allows Local Information Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A SQL injection vulnerability in the Contacts Provider allows unauthorized local information disclosure without requiring user interaction or additional privileges. This could potentially expose sensitive contact data. Confirming relevance and exposure within your environment is advised.

CVE advisoryCRITICAL

CVE-2026-28575

Android PackageInstaller Memory Exhaustion Denial of Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic error in Android's PackageInstaller can cause memory exhaustion, leading to a local denial of service. This vulnerability does not require special access or user interaction to exploit, potentially impacting device operations. The attack vector is local, suggesting a limited external threat.

CVE advisoryCRITICAL

CVE-2026-27429

Nifty Theme PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Nifty WordPress theme. Attackers can exploit this by sending specially crafted requests, potentially leading to remote code execution. This could impact system data and service behavior. Confirming theme usage and external exposure is crucial for asses

CVE advisoryCRITICAL

CVE-2026-27395

Unauthenticated Privilege Escalation in Support Board Prior to 3.8.9

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated privilege escalation vulnerability exists in Support Board, allowing attackers to gain administrative control. This impacts the software's ability to secure system functions and data, necessitating an assessment of its use and potential exposure.

CVE advisoryCRITICAL

CVE-2026-27041

Elementor Unlimited Elements Arbitrary File Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin allows contributor-level users to upload arbitrary files, potentially enabling unauthorized code execution or site compromise. The risk is amplified because this plugin extends website functionality, making it a core component of public-facing web applications. Confirmation of its use and exposure on

CVE advisoryCRITICAL

CVE-2026-25470

WordPress ACPT Plugin Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical code injection vulnerability exists in a WordPress plugin that creates custom post types, potentially allowing remote code inclusion. If reachable, an attacker could execute arbitrary code on the server, impacting site integrity and data. Confirmation of the plugin's usage and its internet accessibility with

CVE advisoryCRITICAL

CVE-2026-25446

WishList Member X Subscriber Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in the WishList Member X plugin, allowing authenticated users to upload malicious files, potentially leading to website compromise. This vulnerability is externally reachable, posing a risk to web application integrity and availability.

CVE advisoryCRITICAL

CVE-2026-24611

MetForm Pro Unauthenticated Broken Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in MetForm Pro, a WordPress plugin, allowing unauthenticated attackers to bypass access controls. This could lead to unauthorized access to sensitive data and disruption of service. Confirming its use is essential to understand potential business risk.

CVE advisoryCRITICAL

CVE-2026-22340

WPJobster Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WPJobster WordPress theme. If reachable, an attacker could send malicious SQL queries to access or modify sensitive data, impacting database integrity and availability. It is important to determine if this theme and version are in use within your web presence

CVE advisoryCRITICAL

CVE-2026-22327

Restaurt Subscriber Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Restaurt theme allows authenticated users to upload arbitrary files, potentially leading to system compromise. If the theme is in use and reachable, attackers could execute malicious code or alter application behavior, posing a risk to integrity and confidentiality. Confirming usage and

CVE advisoryCRITICAL

CVE-2026-12440

Google Chrome DigitalCredentials Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A "use after free" vulnerability in Google Chrome's DigitalCredentials component on Windows could allow a remote attacker to escape the browser's sandbox by tricking a user into visiting a malicious HTML page. This could potentially lead to unauthorized access to system resources or sensitive information.

CVE advisoryCRITICAL

CVE-2026-0092

Android Package Manager Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Android Package Manager that allows for privilege escalation without user interaction. This bypasses device lock controls, potentially impacting device integrity and stored data. The affected technology is a core component of the Android operating system, making it relevant for ov

CVE advisoryCRITICAL

CVE-2026-0083

Android NFC Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Android's NFC component could allow local privilege escalation through a use-after-free error caused by a race condition. This flaw is reachable and relevant for local attacks, and requires no user interaction or additional privileges to exploit, potentially impacting system data and service behavior

CVE advisoryCRITICAL

CVE-2026-0082

Android NfcDispatcher Automatic App Access Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Android's NFC component may allow for automatic special app access permission assignment, leading to local privilege escalation without user interaction. This could potentially affect system and user data by granting elevated privileges.

CVE advisoryCRITICAL

CVE-2026-0081

NFC Event Spoofing Leading to Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in NFC technology allows an attacker to spoof NFC events due to a missing permission check, potentially leading to local privilege escalation. This could impact system integrity and availability. The relevance and exposure of affected systems need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-0071

SettingsLib Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic error in SettingsLib could allow local privilege escalation without further privileges or user interaction, potentially impacting system integrity. The vulnerability's reachability is assessed as very unlikely due to its internal, non-network accessible nature.

CVE advisoryCRITICAL

CVE-2026-0068

Android Package Installer DPC App Removal Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Android Package Installer Service that could allow a malicious app to remove a DPC app without consent, potentially leading to local privilege escalation. Exploitation requires local access and user interaction to install a malicious application. Confirming relevance and exposure on manage

CVE advisoryCRITICAL

CVE-2026-0064

Resource Exhaustion Denial of Service Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists that allows for a persistent denial of service through resource exhaustion. This could disrupt local systems without needing special privileges or user interaction, impacting service availability. The relevance and exposure to our environment are currently uncertain.

CVE advisoryCRITICAL

CVE-2026-0063

Android Privilege Escalation via Carrier Restriction Bypass.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic error in Android's phone interface manager allows for disabling carrier restrictions, potentially leading to local privilege escalation on a device. This vulnerability does not require user interaction or network access. Confirmation is needed to determine the specific relevance and reachability of this flaw wi

CVE advisoryCRITICAL

CVE-2025-69179

Support Ticket Management System Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in a Support Ticket Management System plugin, potentially allowing network-accessible attackers to gain elevated system access. This could lead to unauthorized modification of sensitive ticket data, impacting customer support portal security.

CVE advisoryCRITICAL

CVE-2025-69129

WordPress WooCommerce Scraper Plugin Arbitrary File Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability allows unauthenticated arbitrary file uploads in a WordPress and WooCommerce plugin, potentially leading to site compromise and malicious code execution. It is uncertain if this plugin is used within the organization, requiring confirmation to assess relevant risk.

CVE advisoryCRITICAL

CVE-2025-69122

PHP Object Injection in SeaFood Company Theme

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in SeaFood Company software, potentially enabling attackers to execute arbitrary PHP code remotely. This occurs when the application processes untrusted data, leading to the unserialization of malicious PHP objects, which could compromise the integrity and av

CVE advisoryCRITICAL

CVE-2025-69108

Hot Coffee Theme PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Hot Coffee WordPress theme. This flaw could allow remote attackers to inject malicious PHP objects without needing credentials, potentially leading to unauthorized access, data manipulation, or denial of service. It is important to determine if this th

CVE advisoryCRITICAL

CVE-2026-46945

Oracle iSupport Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle iSupport, allowing a highly privileged attacker with network access to potentially take over the system and impact other connected products. The issue is reachable via HTTP and could lead to a significant compromise of the iSupport application.

CVE advisoryCRITICAL

CVE-2026-46944

Oracle iSupport High Privilege Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle iSupport allows highly privileged attackers with network access to take over the system and potentially impact other connected products. This affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. The issue has a CVSS score of 9.1, indicating high impacts to confidentiality,

CVE advisoryCRITICAL

CVE-2026-46930

Oracle E-Business Suite In-Memory Cost Management Data Tampering Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle In-Memory Cost Management for Discrete Industries, allowing unauthenticated network attackers to gain unauthorized access or modify critical data. This issue could lead to unauthorized creation, deletion, or modification of data, or complete access to all accessible data within

CVE advisoryCRITICAL

CVE-2026-46919

Oracle Siebel CRM Cloud Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component that allows unauthenticated attackers with network access to completely compromise the application. Successful exploitation could lead to a full takeover, impacting data confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46918

Oracle Process Manufacturing Product Development Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Process Manufacturing Product Development, part of Oracle E-Business Suite, allows low-privileged attackers with network access to achieve a complete takeover of the system and potentially impact other products.

CVE advisoryCRITICAL

CVE-2026-46912

JD Edwards EnterpriseOne Tools Web Runtime Security Vulnerability Allows Critical Data Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in JD Edwards EnterpriseOne Tools' Web Runtime Security component, allowing unauthenticated attackers with network access to potentially gain unauthorized access to critical data or modify existing information. This issue may also impact other connected products, making it important to a

CVE advisoryCRITICAL

CVE-2026-46911

JD Edwards EnterpriseOne Project Costing Vulnerability Allows Critical Data Access and Modification.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Project Costing that could allow a low-privileged attacker with network access to modify, delete, or gain unauthorized access to critical project and financial data. The exploit's impact may extend to other JD Edwards products.

CVE advisoryCRITICAL

CVE-2026-46910

Oracle JD Edwards EnterpriseOne Tools Network Access Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools that could allow an unauthenticated attacker with network access to obtain unauthorized access to critical data or cause system crashes, impacting both confidentiality and availability. Because the issue is reachable via HTTP, it poses a risk to b

CVE advisoryCRITICAL

CVE-2026-46908

Oracle JD Edwards EnterpriseOne Accounts Payable Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Accounts Payable, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation could lead to a takeover of the Accounts Payable functionality and potentially impact other connected products, with sign

CVE advisoryCRITICAL

CVE-2026-46907

Oracle JD Edwards Order Promising Integration Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle JD Edwards EnterpriseOne Order Promising integration could allow a low-privileged attacker with network access to take over the system. Successful exploitation may impact additional products, leading to significant risks.

CVE advisoryCRITICAL

CVE-2026-46906

JD Edwards EnterpriseOne Tools Infrastructure Security Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle's JD Edwards EnterpriseOne Tools allows a low-privileged attacker with network access to compromise critical data. Successful exploitation could lead to unauthorized creation, deletion, or modification of sensitive information, potentially impacting additional JD Edwards products. Thi

CVE advisoryCRITICAL

CVE-2026-46905

Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle JD Edwards EnterpriseOne Tools' Web Runtime Security component allows unauthenticated network attackers to achieve a full system takeover. This easily exploitable issue, accessible via HTTP, could impact confidentiality, integrity, and availability. Confirming the relevance and exposu

CVE advisoryCRITICAL

CVE-2026-46904

Oracle JD Edwards EnterpriseOne Tools Vulnerability Allows Unauthenticated Network Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, allowing unauthenticated network attackers to take over the system. This impacts confidentiality, integrity, and availability. It is important to determine if your organization uses the affected technology and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-46902

Oracle Enterprise Command Center Framework Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Enterprise Command Center Framework allows unauthenticated network attackers to take over the system. This could expose sensitive information and grant full control over the framework. Its network-accessible nature makes it a significant risk.

CVE advisoryCRITICAL

CVE-2026-46901

Oracle Enterprise Command Center Framework Remote Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Oracle Enterprise Command Center Framework, part of Oracle E-Business Suite, allowing a low-privileged attacker with network access to compromise the framework. This could lead to unauthorized access, modification, or deletion of critical data, and potentially a partial denial of service,

CVE advisoryCRITICAL

CVE-2026-46900

Oracle Enterprise Command Center Framework Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Enterprise Command Center Framework could allow a low-privileged attacker with network access to take over the framework, potentially impacting other connected products. This could lead to significant loss of confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46899

Oracle ECCF Unauthorized Data Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Enterprise Command Center Framework, part of Oracle E-Business Suite, allows a low-privileged attacker with network access to compromise the framework. This could result in unauthorized modification or access to critical data, potentially impacting additional Oracle products. Organiza

CVE advisoryCRITICAL

CVE-2026-46897

Oracle Enterprise Command Center Framework Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Enterprise Command Center Framework, potentially allowing unauthorized access to and modification of critical data, as well as a partial denial of service. Successful exploitation, achievable by a low-privileged attacker with network access, could impact additional Oracle produ

CVE advisoryCRITICAL

CVE-2026-46896

Oracle Enterprise Command Center Framework Remote Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Enterprise Command Center Framework allows a highly privileged attacker with network access to compromise the framework, potentially impacting other products. Exploitation could lead to a full takeover of the framework.

CVE advisoryCRITICAL

CVE-2026-46893

Oracle JD Edwards EnterpriseOne General Ledger Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle JD Edwards EnterpriseOne General Ledger allows low-privileged attackers with network access to compromise the system, potentially impacting other products and leading to a full takeover. The exact business impact and relevance in your environment are currently under analysis.

CVE advisoryCRITICAL

CVE-2026-46892

Oracle JD Edwards HR Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle JD Edwards EnterpriseOne Human Resources Management allows unauthenticated attackers with network access to compromise critical data. This could result in unauthorized creation, deletion, or modification of sensitive HR information.

CVE advisoryCRITICAL

CVE-2026-46890

Oracle Siebel CRM Marketing Component Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM's Marketing component allows unauthenticated attackers with network access to take over the system, impacting confidentiality, integrity, and availability. This poses a significant risk to business operations due to the ease of exploitation and the value of enterprise CRM s

CVE advisoryCRITICAL

CVE-2026-46875

Oracle Enterprise Manager Deployment Library Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Enterprise Manager Base Platform's Deployment Library component. An attacker with high privileges and network access via HTTPS could exploit this to take over the platform, potentially affecting other connected products. This could impact confidentiality, integrity, and availab

CVE advisoryCRITICAL

CVE-2026-46872

Oracle Enterprise Manager Base Platform Install Vulnerability Allows Data Modification and Denial of Service.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Oracle Enterprise Manager Base Platform's installation component, allowing a high-privilege attacker with network access to compromise the platform. This could lead to unauthorized data modification or deletion, unauthorized data reading, or denial of service by causing the platform to crash.

CVE advisoryCRITICAL

CVE-2026-46861

MySQL NDB Cluster Operator Unauthorized Data Access Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle MySQL NDB Cluster's NDB Operator component could allow a low-privileged attacker with network access to compromise the cluster. Successful exploitation may result in unauthorized access, modification, or deletion of critical data, with potential impact on other products. Uncertainty exists reg

CVE advisoryCRITICAL

CVE-2026-46860

MySQL Router HTTP Vulnerability Allows Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle's MySQL Router allows unauthenticated attackers with network access to take over the router. This easily exploitable issue could impact the confidentiality, integrity, and availability of the router and its managed services. Confirming if MySQL Router is in use is essential.

CVE advisoryCRITICAL

CVE-2026-46859

Oracle Agile PLM Security Vulnerability Allows Full System Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Agile PLM allows unauthenticated attackers with network access to compromise the system and achieve a full takeover. This could impact business operations by affecting confidentiality, integrity, and availability. It is important to determine if Oracle Agile PLM is in use and exposed

CVE advisoryCRITICAL

CVE-2026-46858

Oracle Enterprise Manager APM Vulnerability Allows Data Manipulation and Denial of Service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Enterprise Manager's Application Performance Management component, allowing unauthenticated network attackers to gain unauthorized access, modify or delete critical data, and cause denial of service. This issue impacts both data integrity and system availability, necessitating

CVE advisoryCRITICAL

CVE-2026-46857

Oracle Enterprise Manager Base Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Enterprise Manager Base Platform allows unauthenticated network attackers to compromise the system, potentially leading to a complete takeover. This issue affects the confidentiality, integrity, and availability of the platform and its managed resources, making it a significant concer

CVE advisoryCRITICAL

CVE-2026-46855

Oracle Enterprise Manager Base Platform Metadata Plugin Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Enterprise Manager Base Platform that allows a low-privileged attacker with network access to compromise the system. Successful exploitation could lead to a complete takeover of the platform and potentially impact other connected products, affecting confidentiality, integrity,

CVE advisoryCRITICAL

CVE-2026-46854

Oracle Enterprise Manager Base Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Enterprise Manager Base Platform allows a low-privileged attacker with network access to compromise the system. Successful exploitation could lead to a complete takeover of the platform, impacting other connected products and potentially causing significant data loss or unauthorized a

CVE advisoryCRITICAL

CVE-2026-46853

Oracle Enterprise Manager Base Platform Metadata Plugin Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Enterprise Manager Base Platform, allowing unauthenticated attackers with network access to achieve platform takeover through user interaction. This issue could impact additional products beyond the Base Platform itself, necessitating a review of affected instances and their cr

CVE advisoryCRITICAL

CVE-2026-46852

Oracle Enterprise Manager Base Platform Metadata Plugin Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Enterprise Manager Base Platform allows a low-privileged attacker with network access to take over the platform and potentially impact other products. This could lead to a complete compromise of confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46850

MySQL Shell for VS Code Remote Takeover Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in MySQL Shell for VS Code, allowing a low-privileged attacker with network access to compromise the shell and potentially affect other products. This easily exploitable flaw could lead to a complete takeover of MySQL Shell, impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46847

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal that allows a low-privileged attacker with network access to take over the system. Successful exploitation can lead to significant impacts on confidentiality, integrity, and availability, potentially affecting other connected products.

CVE advisoryCRITICAL

CVE-2026-46832

Oracle Enterprise Manager Discovery Framework Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Enterprise Manager Base Platform's Discovery Framework allows a low-privileged attacker with network access to compromise the platform, potentially impacting other connected products. Successful exploitation could lead to a full takeover of the Oracle Enterprise Manager Base Platform. This iss

CVE advisoryCRITICAL

CVE-2026-46794

Oracle Identity Manager Connector SSH Takeover Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Fusion Middleware's Identity Manager Connector allows a low-privileged attacker with network access via SSH to compromise the connector. This could lead to a complete takeover of the Identity Manager Connector and potentially impact other integrated products, affecting confidentiality, integri

CVE advisoryCRITICAL

CVE-2026-46793

Oracle Identity Manager Connector Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Fusion Middleware's Identity Manager Connector could allow a low-privileged attacker with network access to take over the connector, potentially impacting other connected products. This vulnerability, easily exploitable via HTTP, poses a significant risk to confidentiality, integrity,

CVE advisoryCRITICAL

CVE-2026-46792

Oracle Identity Manager Connector Remote Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle's Identity Manager Connector allows a low-privileged attacker with network access to potentially take over the connector, impacting other products and systems. <tool_code print(google_search.search(queries=["Oracle Identity Manager Connector Generic Unix Connector vulnerability", "Ora

CVE advisoryCRITICAL

CVE-2026-46789

Oracle WebCenter Content Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Content could allow unauthenticated attackers to take over the system via network access, requiring user interaction. This could impact the confidentiality, integrity, and availability of content management and potentially other connected products.

CVE advisoryCRITICAL

CVE-2026-46786

Oracle WebCenter Content Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Content allows unauthenticated network attackers to take over the system, potentially impacting other products. Exploitation requires user interaction and can lead to full system compromise. This issue is reachable externally and warrants attention due to its potential scope

CVE advisoryCRITICAL

CVE-2026-46785

Oracle WebCenter Content HTTP Access Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Content, allowing unauthenticated network attackers to modify or access sensitive data. Exploitation requires user interaction and can impact other products. This could lead to unauthorized data creation, deletion, modification, or complete access.

CVE advisoryCRITICAL

CVE-2026-46784

Oracle WebCenter Content Imaging Unauthorized Data Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Content: Imaging, allowing unauthenticated attackers with network access to compromise critical data. Successful exploitation could lead to unauthorized creation, deletion, or modification of data, or complete access to all accessible data within the system. This impa

CVE advisoryCRITICAL

CVE-2026-35270

Oracle WebCenter Content Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Content allows a high-privileged attacker with network access via HTTP to compromise the system, potentially leading to a complete takeover. While the vulnerability resides in WebCenter Content, successful exploitation could impact additional products. This issue is relevant

CVE advisoryCRITICAL

CVE-2026-35268

Oracle Fusion Middleware Identity Manager Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Fusion Middleware Identity Manager allows a low-privileged attacker with network access to potentially take over the system, impacting connected products. The vulnerability, which affects core identity management functions, carries a high severity score, indicating severe impacts on c

CVE advisoryCRITICAL

CVE-2026-35263

Oracle WebLogic Server Remote Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server, accessible via HTTP, could allow a low-privileged attacker to gain complete control of the server and potentially impact other connected products. This issue requires attention from teams managing the application and its infrastructure to identify instances, assess ex