NVD disclosure day

Published threat advisories for July 17, 2026

CVE advisoryCRITICAL

CVE-2026-55518

Avo Association Attachment Vulnerability Allows Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Avo framework, used for Ruby on Rails admin panels, has a vulnerability where low-privileged users can attach records bypassing UI controls. This could lead to privilege escalation or cross-tenant data exposure if associations represent authorization.

CVE advisoryCRITICAL

CVE-2026-54466

websocket-driver Integer Overflow Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WebSocket protocol handler allows an attacker to send specially crafted data, causing an integer overflow that can lead to incorrect parsing of subsequent data. This could potentially result in service disruptions or instability. The primary concern is to determine if this technology is in use and

CVE advisoryCRITICAL

CVE-2026-54159

PrestaShop ps_facetedsearch Webshell via Unserialized Input

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the PrestaShop ps_facetedsearch module, allowing unauthenticated attackers to execute arbitrary code on the server. By manipulating URL parameters, an attacker can inject malicious code that, when processed by the module, results in a webshell being written to the server. This could l

CVE advisoryCRITICAL

CVE-2026-52348

Cool-Admin-Java Order Method SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the order() method of CrudOption.java within cool-admin-java. This flaw, if reachable, could permit unauthorized SQL command execution, potentially affecting data confidentiality, integrity, and availability. This administrative framework is often internet-facing, making it a con

CVE advisoryCRITICAL

CVE-2026-48062

CodeIgniter Upload Validation Bypass Allows Arbitrary Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the CodeIgniter PHP framework could allow arbitrary code execution if an application accepts user-controlled uploads and incorrectly validates file types. This flaw enables malicious scripts disguised as safe files to be uploaded and run, impacting organizations that store user uploads in web-accessi

CVE advisoryCRITICAL

CVE-2026-13446

IBM Langflow OSS Hard-Coded Credentials Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS contains hard-coded credentials, which attackers could exploit if the software is accessible. This vulnerability may allow unauthorized access to sensitive information or system functions. Confirming its use within your organization is recommended.

CVE advisoryCRITICAL

CVE-2026-8859

IBM Langflow APIRequest Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS is vulnerable to path traversal, allowing an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. This occurs when the "Save to File" feature is enabled, and crafted filenames from an external HTTP server bypass sanitization, potentiall

CVE advisoryCRITICAL

CVE-2026-8635

IBM Langflow OSS Privilege Escalation and Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS has a critical vulnerability allowing authenticated users to escalate privileges and execute system commands by manipulating its database, potentially leading to full system compromise. It's important to confirm if Langflow OSS is deployed and reachable, as this could expose the system to significant r

CVE advisoryCRITICAL

CVE-2026-8505

IBM Langflow OSS Authentication Bypass Enables Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IBM Langflow OSS has a vulnerability in its webhook authentication that allows unauthenticated users to execute any flow if API key validation is bypassed by the default configuration. An attacker knowing a flow's UUID could trigger its execution, potentially leading to remote code execution. This is relevant if your L

CVE advisoryCRITICAL

CVE-2026-8481

IBM Langflow OSS Code Validation API Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in IBM Langflow OSS allows authenticated users to execute arbitrary system commands by sending Python code to a validation API endpoint. This API directly executes user-supplied code without validation or sandboxing, granting attackers full privileges on the Langflow server if the endpoint is r

CVE advisoryCRITICAL

CVE-2026-8476

IBM Langflow OSS RCE via Unsafe Pickle Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS has a critical vulnerability where an unsafe deserialization of cached data via disk-based caching can allow attackers to execute arbitrary code, potentially leading to complete system compromise. This issue is relevant if an attacker can influence cached data through various means, making the Langflow

CVE advisoryKnown Exploit

CVE-2026-63030

WordPress REST API Route Confusion and SQL Injection Leading to RCE

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A route confusion flaw in WordPress's REST API, when combined with a separate SQL injection vulnerability, could allow an unauthenticated attacker to execute arbitrary code on affected systems. This could lead to a significant compromise of the WordPress installation if the vulnerability is reachable.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-60137

WordPress SQL Injection via WP_Query Author Not In Parameter

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in WordPress could permit SQL injection attacks if themes or plugins pass untrusted input to the `author__not_in` parameter in `WP_Query`. This flaw is externally reachable and could lead to unauthorized data access or modification.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-52199

UZ801_v2.1 4G LTE Router Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in a 4G LTE router, specifically in the `sbin/adbd` component, allowing remote attackers to execute arbitrary code. This could impact the device's functionality and the network it manages, especially if its administrative or service components are exposed to the internet. The primary con

CVE advisoryCRITICAL

CVE-2026-46420

GitHub Action setup-php Command Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability in the setup-php GitHub action allows an attacker to execute arbitrary commands on a GitHub Actions runner. This can occur if an attacker controls files in a repository that are processed by the setup-php action. The vulnerability is present in versions prior to 2.37.1.

CVE advisoryCRITICAL

CVE-2026-36669

Feng Office Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Feng Office allows unauthenticated attackers to upload malicious files to the web server. This could lead to the execution of harmful code or system compromise if the upload handler is reachable. Organizations using Feng Office should confirm its relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-15091

IBM Engineering AI Hub Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in IBM Engineering AI Hub that could allow remote attackers to execute arbitrary scripts by improperly handling web page input. This could potentially lead to the exposure of sensitive information or unauthorized actions within the affected system if reachable. Organizations should confi

CVE advisoryCRITICAL

CVE-2026-13473

IBM Storage Protect Heap-Based Buffer Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM Storage Protect client has a critical heap-based buffer overflow vulnerability that could allow remote attackers to execute code or crash the system. This is due to improper bounds checking, which could enable an attacker to gain control or disrupt service availability.

CVE advisoryCRITICAL

CVE-2025-51677

openRISC OR1200 RTL Netlist Mismatch Leading to Unexpected Behavior

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An output mismatch in the openRISC OR1200 CPU design between its RTL and netlist can lead to unexpected behavior. While this vulnerability exists at the hardware logic level and is unlikely to be directly reachable from external networks, its impact could affect system operations. Readers should care to confirm if this

CVE advisoryCRITICAL

CVE-2026-9135

IBM Langflow OSS Code Injection Leading to Server-Side Python Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability in IBM Langflow OSS affects its Policies component, enabling authenticated users with flow creation privileges to bypass security controls and execute arbitrary Python code on the server. This occurs because dynamic CodeInput fields are not properly validated, allowing malicious Python co

CVE advisoryCRITICAL

CVE-2026-9103

IBM Langflow OSS Auto-Login Vulnerability Grants Unauthenticated Administrative Access.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IBM Langflow OSS has a vulnerability in its auto-login feature that could allow unauthenticated attackers to gain administrative access. The affected API endpoint issues administrative tokens without requiring authentication when the feature is enabled by default. Permissive security settings might also expose these to

CVE advisoryCRITICAL

CVE-2026-9202

IBM Langflow Account Creation Vulnerability Allows RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in IBM Langflow OSS allows unauthenticated attackers to create an unlimited number of active user accounts. If a specific deployment option is enabled, these accounts can immediately authenticate and access remote code execution endpoints. This could lead to unauthorized system access and compromise.

CVE advisoryKnown Exploit

CVE-2026-9198

IBM Langflow OSS RCE via Authentication Bypass and Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IBM Langflow OSS has a critical vulnerability where unauthenticated attackers can execute arbitrary code and mint administrative tokens by chaining two API calls. This allows for full remote code execution on affected deployments.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-8297

GisLab Laboratory Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in the GisLab Laboratory Management System could allow attackers to execute unauthorized SQL commands, potentially leading to data compromise. This issue is reachable via the network and affects systems managing laboratory data. Confirming system usage and exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-54496

ZEBRA Node Vulnerability Allows Undetected Diversified Address Integrity Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Zcash node software's cryptographic components could permit a malicious prover to create a valid proof for an Orchard Action with an under-constrained base point. This may bypass integrity checks that bind keys and identifiers to the note being spent, potentially affecting transaction data accuracy.

CVE advisoryCRITICAL

CVE-2026-12694

Vimesoft Enterprise Video Platform Missing Authorization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authorization vulnerability in Vimesoft Enterprise Video Platform allows unauthenticated network access to sensitive functions. This could lead to unauthorized modifications or service disruptions, making it important to confirm if your organization uses this platform and is exposed.

CVE advisoryCRITICAL

CVE-2026-12693

Vimesoft Enterprise Video Platform Authorization Bypass Allows Unrestricted Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Vimesoft Enterprise Video Platform allowing authorization bypass. This could enable unauthorized access to restricted functionalities. It is important to determine if this technology is relevant and exposed within our environment.

CVE advisoryCRITICAL

CVE-2026-12692

Vimesoft Enterprise Video Platform Unverified Password Change Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unverified password change vulnerability in Vimesoft Enterprise Video Platform can lead to authentication bypass. This critical, externally exposed issue allows unauthenticated network access, potentially impacting data and operations. Confirming platform usage and assessing exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-60024

Events Booking Unauthenticated Media Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Events Booking Joomla extension has a critical vulnerability that permits unauthenticated users to upload media assets. This could allow unauthorized access to and modification of web content if the extension is in use and reachable. Confirming its presence is advised.

CVE advisoryCRITICAL

CVE-2026-51080

Proxmox Storage Libraries XXE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical XML External Entity (XXE) vulnerability exists in Proxmox Virtual Environment storage management libraries. This flaw, if reachable, could allow an unauthenticated remote attacker to access sensitive system information, modify data, or disrupt services by sending malicious XML input. Confirming the relevance

CVE advisoryCRITICAL

CVE-2024-23564

HCL Aftermarket EPC Password Exposure Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A business logic vulnerability exists in HCL Aftermarket EPC, allowing unauthorized users to obtain server passwords and redirect them to their own email addresses by manipulating server responses. This occurs because the application inadequately validates email requests for password delivery, potentially exposing cred

CVE advisoryCRITICAL

CVE-2026-9810

AI Copilot WordPress Plugin Administrator Session Hijacking Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the AI Copilot WordPress plugin allows unauthenticated attackers to gain administrator privileges by exploiting how OAuth access tokens are handled. This could enable unauthorized actions like creating users or escalating roles on affected websites if the plugin is exposed externally.

CVE advisoryCRITICAL

CVE-2026-62241

Clawvet API JWT Secret Vulnerability Allows Session Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the clawvet self-hosted API server allows unauthenticated remote attackers to obtain sensitive user data by forging session cookies offline with a hard-coded secret. This could expose user email addresses, subscription plans, and API keys if the server is reachable.

CVE advisoryCRITICAL

CVE-2026-62232

Grav Login Plugin 2FA Bypass Allows Password-Only Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Grav's login plugin permits attackers who know a victim's password to bypass two-factor authentication. By triggering a two-factor secret regeneration, an attacker can replace the legitimate secret with their own, compute a valid code, and gain unauthorized access. This flaw reduces two-factor authen

CVE advisoryCRITICAL

CVE-2026-14956

Bricksforge WordPress Plugin Privilege Escalation Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Bricksforge WordPress plugin has a privilege escalation vulnerability allowing unauthenticated attackers to create new administrator accounts. This is possible via a public Pro Forms registration form due to improper validation of attacker-supplied field IDs. The risk exists if your site uses this plugin with publi