NVD disclosure day

Published threat advisories for June 18, 2026

CVE advisoryHIGH

CVE-2026-54130

M365 Copilot Missing Authentication Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in M365 Copilot could allow unauthorized network access to disclose sensitive information. This issue impacts confidentiality and potentially integrity and availability. You should care because it affects a network-accessible productivity tool.

CVE advisoryCRITICAL

CVE-2026-47647

Microsoft Dynamics 365 Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical privilege escalation vulnerability exists in Microsoft Dynamics 365 due to improper access controls, allowing an authenticated attacker to elevate privileges over a network. This could impact system control and data integrity for internet-facing business and ERP applications.

CVE advisoryCRITICAL

CVE-2026-49257

mcp-pinot Unauthenticated Access Grants Full Apache Pinot Cluster Control

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The mcp-pinot tool, used for interacting with Apache Pinot, has a vulnerability allowing unauthenticated network access to execute commands, modify data, and gain full control of the connected Pinot cluster. This issue arises from default insecure configurations that do not require authentication and proxy user request

CVE advisoryCRITICAL

CVE-2026-49252

Deepstream Prototype Pollution Enables Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A prototype pollution vulnerability in the deepstream server, a technology used for real-time data synchronization and communication, could allow an authenticated user with write permissions to escalate their privileges. This could potentially impact system integrity and data confidentiality.

CVE advisoryCRITICAL

CVE-2026-43994

Coturn OAuth Stack Buffer Overflow Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack buffer overflow exists in Coturn, an open-source server for WebRTC communication, when using OAuth mode. Attackers can exploit this by sending a crafted token, potentially leading to remote code execution. Given Coturn's widespread use for internet-based communication, this vulnerability could have broad impact

CVE advisoryCRITICAL

CVE-2026-47846

Bitnami Cassandra Container Retained Default Superuser Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Bitnami Cassandra container images contain a retained default superuser vulnerability. This allows an unintended access path, potentially leading to unauthorized database control if the default `cassandra` superuser account remains active.

CVE advisoryCRITICAL

CVE-2026-54390

JTL Shop Server-Side Template Injection Command Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A server-side template injection vulnerability in JTL Shop allows unauthenticated attackers to inject malicious syntax due to unsanitized input. This could lead to the disclosure of sensitive server data, and on some versions, the execution of arbitrary commands.

CVE advisoryCRITICAL

CVE-2026-56020

Webmin HTTP Server User Impersonation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Webmin HTTP server contains a critical vulnerability that allows unauthenticated attackers to impersonate any user by sending a forged HTTP header that spoofs a valid SSL client certificate. This could lead to unauthorized access to server functions and data. It is important to identify if this technology is in use

CVE advisoryCRITICAL

CVE-2026-55203

HAProxy Integer Overflow Allows FastCGI Record Misparse

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in HAProxy allows a malicious FastCGI backend to cause buffer misparsing by exploiting an integer overflow. This can lead to desynchronization of the FastCGI framing parser, potentially resulting in request routing errors, response smuggling, or memory safety issues.

CVE advisoryCRITICAL

CVE-2026-38715

InHand Router Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in InHand Networks industrial routers' log viewing function, allowing unauthenticated remote attackers to execute arbitrary commands as root. Because these routers are often internet-facing, this could lead to device compromise. Confirmation of affected devices within our enviro

CVE advisoryCRITICAL

CVE-2026-38714

InHand Networks Routers Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in InHand Networks devices, enabling remote attackers to execute arbitrary commands as root without authentication. This could lead to a complete compromise of the affected devices and any data they process or store.

CVE advisoryCRITICAL

CVE-2026-8024

ibaPDA and ibaDatCoordinator Deserialization Vulnerability Allows Full System Access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A deserialization vulnerability in ibaPDA or ibaDatCoordinator allows remote, unauthenticated attackers to gain full system access. This means an attacker could potentially control the affected systems without needing any credentials. The primary concern is to determine if these systems are in use and reachable, as the

CVE advisoryCRITICAL

CVE-2026-54419

PIAF-HMS Unauthenticated SQL Injection Vulnerabilities.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

PIAF-HMS is a hotel management system with multiple unauthenticated SQL injection vulnerabilities. Unauthenticated attackers can inject SQL code to read, modify, or delete arbitrary records in the database, posing a risk to sensitive data. The system's network exposure and lack of authentication make it a target.

CVE advisoryCRITICAL

CVE-2026-11718

googleapis/mcp-toolbox Authentication Bypass via Opaque Token Validation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in the mcp-toolbox allows the acceptance of tokens from unauthorized identity providers. This occurs when an external OAuth provider omits the issuer field in its introspection response, causing the toolbox to skip necessary validation logic. This could lead to unintended access t

CVE advisoryCRITICAL

CVE-2026-11717

mcp-toolbox Authentication Bypass via Opaque Token Validation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the `mcp-toolbox` allows an attacker to bypass authentication by exploiting how opaque tokens are validated. If an introspection endpoint omits the mandatory "active" field in its response, the `mcp-toolbox` may grant unauthorized access to protected tools and data sources. This issue is relevant if

CVE advisoryCRITICAL

CVE-2025-10560

Worksnaps Client Hardcoded Cloud Credentials Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Worksnaps client applications contain hardcoded cloud credentials, including AWS access keys and S3 bucket information. An attacker with access to the client binaries could extract these credentials to gain unauthorized access to sensitive production cloud resources, such as user desktop screenshots. The risk is contin

CVE advisoryCRITICAL

CVE-2026-55742

Cotonti CSRF Vulnerability Escalates Privileges

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Cross-Site Request Forgery vulnerability exists in the Cotonti administration rights handler. Remote attackers can exploit this by tricking an authenticated administrator into visiting a malicious page, which could allow them to elevate privileges to administrator level. This could lead to unauthorized modif

CVE advisoryCRITICAL

CVE-2026-55740

Nur-Alam39 bus-ticket bus_info.php SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in a bus ticketing application allows unauthenticated attackers to execute arbitrary SQL commands and access sensitive database data. The flaw, located in bus_info.php, stems from unsanitized input, and the application's use of the MySQL root account with an empty password amplifi

CVE advisoryKnown Exploit

CVE-2026-12569

PTC Windchill and FlexPLM Remote Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical remote code execution vulnerability exists in PTC Windchill PDMlink and PTC FlexPLM due to improper deserialization of untrusted data. This could allow an attacker to execute arbitrary code on affected systems, potentially impacting sensitive product design and engineering data. Confirm the relevance and exp

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-48768

Typebot Arbitrary Content Upload and Stored XSS via Unauthenticated File Input

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability in TypeBot allows anonymous visitors to upload malicious files. This could lead to arbitrary content hosting and cross-site scripting attacks on the storage origin. Please confirm if TypeBot is used within your organization.