NVD disclosure day

Published threat advisories for July 7, 2026

CVE advisoryCRITICAL

CVE-2026-59705

mem0 OpenMemory API Unauthenticated Memory Access and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated access vulnerability exists in mem0's openmemory/api component, allowing attackers to read, write, or delete arbitrary user memories. Attackers can also trigger a denial-of-service affecting all users. This issue is relevant for readers to understand potential unauthorized access to sensitive data an

CVE advisoryCRITICAL

CVE-2026-37271

Fire-Boltt Smartwatch Improper Authentication via BLE Packet Replay

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Fire-Boltt Smartwatch firmware has a critical Improper Authentication vulnerability where a device accepts GATT Write Request commands without sufficient validation. This allows previously captured Bluetooth Low Energy (BLE) packets to be replayed from a nearby device, potentially triggering unauthorized functionality.

CVE advisoryCRITICAL

CVE-2026-37270

Trueview Security Camera T18161-AF Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass vulnerability exists in Trueview Security camera firmware due to improper password validation and hard-coded credentials. If reachable, this could allow unauthenticated attackers to gain administrative control of the camera.

CVE advisoryCRITICAL

CVE-2026-14740

DBI for Perl Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in a Perl database interface module that could lead to application crashes or unpredictable behavior. The issue involves an out-of-bounds read when processing SQL comments, potentially causing faults or unintended data handling. While direct exploitation is considered unlikely due to the

CVE advisoryCRITICAL

CVE-2026-14739

DBI Heap Overflow with Excessive Placeholders.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap overflow vulnerability exists in a Perl database interface library that can occur when preparsing SQL statements with a vast number of placeholders. This issue could potentially lead to denial-of-service conditions or system compromise if triggered by an attacker. It is important to determine if systems use this

CVE advisoryCRITICAL

CVE-2026-59706

Mem0 Config API Vulnerability Exposes LLM Keys and Enables SSRF

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Unauthenticated access to mem0's configuration API endpoints can expose LLM API keys and enable server-side request forgery, allowing attackers to retrieve secrets or target internal systems. This vulnerability is reachable as the affected API endpoints are network-accessible.

CVE advisoryCRITICAL

CVE-2026-46354

Coder Azure Identity Validation Vulnerability Allows Session Token Theft.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Coder's remote development environment provisioning could allow an unauthenticated attacker to embed malicious content in a certificate to obtain a victim's session token. This requires the attacker to know the target VM's ID.

CVE advisoryCRITICAL

CVE-2026-59707

LocalAI SSRF via Unsanitized Model Apply Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint. This allows attackers to fetch arbitrary internal URLs by forcing the server to issue HTTP GET requests to private and loopback addresses, potentially leaking partial response content. This is relevant if L

CVE advisoryCRITICAL

CVE-2026-59800

9Router OS Command Injection via Tailscale Install API

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability exists in 9Router software, allowing unauthenticated remote attackers to execute arbitrary commands. This occurs when a `sudoPassword` field in an API request is processed by a shell, and specific conditions bypass the need for a password prompt, leading to potential system comprom

CVE advisoryCRITICAL

CVE-2026-13020

Esri Portal for ArcGIS Weak Password Recovery Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A weakness in Esri Portal for ArcGIS's password recovery mechanism may allow remote attackers to take over user accounts. This vulnerability affects systems running version 12.1 and earlier. While administrator password resets are unaffected, proper configuration of email for self-service recovery is advised.

CVE advisoryCRITICAL

CVE-2026-13019

Esri Portal for ArcGIS Missing Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Esri Portal for ArcGIS, enabling remote, unauthenticated attackers to access unprotected APIs. This could impact the confidentiality, integrity, and availability of the system and its managed data. Its common use as an internet-facing geographic information system portal or API gatewa

CVE advisoryCRITICAL

CVE-2026-53483

Dell PowerProtect Data Domain Improper Authentication Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Dell PowerProtect Data Domain has an improper authentication vulnerability that an unauthenticated remote attacker could exploit for complete system control. This impacts data protection and backup systems, making it critical to confirm relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-53481

Dell PowerProtect Data Domain Path Traversal Vulnerability Allows System Takeover.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in Dell PowerProtect Data Domain allows unauthenticated remote attackers to gain unauthorized system access, potentially leading to complete control. This critical vulnerability requires prompt attention to mitigate risks associated with unauthorized system compromise.

CVE advisoryCRITICAL

CVE-2011-10043

Module::Load Arbitrary Module Load Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a Perl module allows attackers to load arbitrary modules by manipulating module names, potentially leading to arbitrary code execution if an attacker can influence the input to the module loading function. This could result in system compromise. The relevance and exposure of this vulnerability within

CVE advisoryCRITICAL

CVE-2026-33264

Apache Airflow Remote Code Execution via Deserialization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Apache Airflow's deserialization process, allowing a malicious DAG author to execute arbitrary code on the API server or scheduler. This could compromise critical orchestration systems, and its relevance hinges on the exposure and trustworthiness of Airflow deployments.

CVE advisoryCRITICAL

CVE-2026-4375

WordPress Plugin RCE via Unauthorized Extension Installation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in certain WordPress plugins, allowing remote code execution. This could enable attackers to compromise affected websites by exploiting a flaw in how extensions are installed or by leveraging vulnerable plugin features. It is important to confirm if these plugins are in use to assess pot

CVE advisoryCRITICAL

CVE-2026-14345

WPFunnels WooCommerce Plugin Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The WPFunnels – Funnel Builder for WooCommerce plugin has a remote code execution vulnerability that unauthenticated attackers can exploit via the 'postData' parameter. This could allow arbitrary code execution on the server if the plugin's logging is enabled and an administrator views the log file.

CVE advisoryCRITICAL

CVE-2026-12375

Uncanny Automator Pro WordPress Plugin Backdoor Leads to Administrator Session Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A compromise in the distribution infrastructure for the Uncanny Automator Pro WordPress plugin introduced a backdoor, allowing unauthenticated attackers to gain administrator sessions and exfiltrate sensitive site information.

CVE advisoryCRITICAL

CVE-2026-34048

Coolify Command Execution Vulnerability via Unauthorized Terminal Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in Coolify's terminal websocket routes, allowing low-privileged users to execute commands on team servers. This could lead to unauthorized access and control over managed systems. Readers should care due to the potential impact on system integrity and data confidentiality.

CVE advisoryCRITICAL

CVE-2026-34047

Coolify Terminal WebSocket Authorization Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Coolify, a server management tool, allows authenticated users to access unauthorized terminal functions, potentially leading to command execution on unintended resources. This issue impacts systems managing servers and applications, and should be reviewed for relevance and potential exposure.

CVE advisoryCRITICAL

CVE-2026-34037

Coolify Cross-Tenant Resource Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Coolify allows authenticated users to clone resources across tenant boundaries, potentially exposing and allowing modification of other teams' data. This occurs due to improper authorization when resolving destination resources, making cross-tenant data access possible. Understanding if Cool