NVD disclosure day

Published threat advisories for July 20, 2026

CVE advisoryHIGH

CVE-2026-15902

Chrome Use After Free Vulnerability Allows Sandbox Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome could allow a remote attacker to execute arbitrary code within the browser's sandbox if a user visits a specially crafted HTML page. This could potentially impact the integrity and confidentiality of data processed by the browser.

CVE advisoryCRITICAL

CVE-2026-15901

Chrome Network Use After Free Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's network component may allow a remote attacker to exploit heap corruption via a crafted HTML page, potentially leading to system compromise. The concern lies in confirming the relevance and exposure of this critical vulnerability given its widespread use.

CVE advisoryCRITICAL

CVE-2026-15900

Chrome for Android GPU Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the GPU component of Google Chrome on Android. If a user visits a specially crafted HTML page, a remote attacker could exploit this flaw to potentially escape the browser's sandbox. This could allow malicious code to execute outside its intended isolated environment, posing a se

CVE advisoryCRITICAL

CVE-2026-15899

Chrome CameraCapture Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's CameraCapture component on Mac could allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This could potentially grant an attacker broader system access. The relevance depends on user interaction with malicious web content.

CVE advisoryCRITICAL

CVE-2026-64625

AVideo Live Plugin OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo contains an OS command injection vulnerability in its Live plugin due to an incomplete fix for a prior issue. This flaw allows unauthenticated, remote attackers to execute arbitrary OS commands via the on_publish.php endpoint. This could lead to a compromise of the affected system.

CVE advisoryCRITICAL

CVE-2026-52656

SJCAM AllWinner Tech FEX File Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An unauthenticated attacker can execute arbitrary code on SJCAM and Whitelabel products by providing a crafted FEX file. The potential impact includes unauthorized control or data compromise. Confirmation of device usage and network exposure is needed to determine relevance.

CVE advisoryCRITICAL

CVE-2024-51315

Tenda TX9 Firmware Stack Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Tenda wireless router firmware has a critical stack overflow vulnerability in its device naming function. If reachable, this flaw could permit unauthorized code execution, potentially compromising network confidentiality, integrity, and availability. Organizations should confirm if this technology is deployed to assess

CVE advisoryCRITICAL

CVE-2026-53595

FreeScout Account Takeover via Public Setup Endpoint

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in FreeScout allows unauthenticated attackers to take over accounts by manipulating the user setup process. An attacker can overwrite an existing user's email and password, potentially gaining access to support agent or administrator accounts. This issue is reachable via a public endpoint and d

CVE advisoryCRITICAL

CVE-2026-13380

VSee Clinic Cleartext SFTP Credential Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in VSee Clinic and its API allows unauthenticated remote attackers to expose cleartext SFTP credentials. This occurs when SFTP is configured, as credentials are included in the HTTP responses of unauthenticated endpoints. An attacker could obtain these credentials and access the SFTP server, potentially

CVE advisoryCRITICAL

CVE-2024-51313

Tenda TX9 Firmware Stack Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack overflow vulnerability exists in the Tenda TX9 firmware's `/goform/SetVirtualServerCfg` function, potentially allowing unauthenticated attackers to compromise network services. If reachable, this could impact device confidentiality, integrity, and availability, necessitating verification of device usage and exp

CVE advisoryCRITICAL

CVE-2024-51311

Tenda TX9 Firmware Stack Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack overflow vulnerability exists in Tenda TX9 firmware's network control list function. Unauthenticated attackers could exploit this remotely to cause denial of service or other system disruption. This warrants attention for devices with internet-facing web interfaces.

CVE advisoryCRITICAL

CVE-2026-63766

GPT-SoVITS OS Command Injection via Web UI

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in GPT-SoVITS's web UI where unsanitized user input is directly used in shell commands. This could allow unauthenticated attackers to execute arbitrary OS commands on the server. Confirming if this technology is in use is crucial to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-64193

Net::DNS Perl Module Remote Code Execution via EDNS Extended Error.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the Net::DNS Perl module that may allow for remote code execution. The issue stems from how the library processes specific DNS data, potentially enabling an attacker to inject and run malicious commands on a system if a vulnerable application receives a specially crafted DNS query. Th

CVE advisoryCRITICAL

CVE-2026-62414

Joomla Page Builder CK Frontend Page List Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Joomla extension for building pages has an access control flaw in its frontend page list views. This could allow unauthenticated users to access sensitive information, or potentially modify content, if the extension is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-61900

Joomla JDownloads Unauthenticated File Upload Leading to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Joomla extension JDownloads has a critical vulnerability allowing unauthenticated file uploads. This could enable remote code execution on affected systems. Attackers can exploit this by uploading malicious files, potentially compromising the integrity and availability of the web application. Confirming its presenc

CVE advisoryCRITICAL

CVE-2026-61424

DJ-Classifieds Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the DJ-Classifieds Joomla extension that allows unauthenticated attackers to upload files and achieve remote code execution. This issue could enable an attacker to gain complete control of a server if the extension is present and reachable. Organizations should confirm if DJ-Classifie

CVE advisoryCRITICAL

CVE-2026-60032

Joomla JMedia Arbitrary File Upload Leading to RCE

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Joomla JMedia extension permits authenticated users to upload and execute arbitrary files, potentially leading to remote code execution on the server. This means an attacker who has already gained administrative access to the Joomla interface could exploit this flaw to control the server, making

CVE advisoryCRITICAL

CVE-2026-39878

Chamilo LMS Stored XSS in Registration Form Allows Admin Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in the Chamilo LMS user registration form. This allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser, potentially leading to full admin account takeover and platform control.

CVE advisoryCRITICAL

CVE-2026-54051

Network-AI Command Injection via Shell Metacharacters in Allowlist Bypass.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Network-AI, a multi-agent orchestrator, where broad wildcard allowlist entries can be bypassed to execute arbitrary shell commands. This occurs because the system's shell processing can misinterpret commands, allowing unintended execution if an attacker gains control of an agent.

CVE advisoryCRITICAL

CVE-2026-41521

xrdp Integer Overflow Leads to Information Disclosure and DoS

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An integer overflow vulnerability in xrdp's processing of screen updates in vnc-any connection mode could allow an unauthenticated remote attacker to disclose sensitive heap memory or cause a denial of service. This occurs if an xrdp server connects to a malicious VNC server.

CVE advisoryCRITICAL

CVE-2026-41252

xrdp vnc-any Heap Overflow Leads to Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker in control of a VNC server can exploit a heap-based buffer overflow in xrdp's vnc-any mode by sending crafted color map messages. This memory corruption can lead to denial of service or remote code execution. The vulnerability's impact depends on whether xrdp is used in this specific mode an

CVE advisoryCRITICAL

CVE-2026-35048

Piwigo Installer Arbitrary Code Execution via Unsanitized POST Parameters

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Piwigo installer allows unauthenticated attackers to execute arbitrary PHP code by sending crafted POST parameters, which are written to a configuration file without proper sanitization, especially on PHP 8+. This could lead to the compromise of the Piwigo application.

CVE advisoryCRITICAL

CVE-2026-51027

FileThingie ft2.php Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in FileThingie's ft2.php component could allow a remote attacker to obtain sensitive information. This issue may impact data confidentiality and integrity if the component is reachable. Readers should confirm FileThingie's presence and exposure in their environment.

CVE advisoryCRITICAL

CVE-2026-46428

Lettre Boring-TLS Disables Hostname Verification

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the `lettre` Rust email library's `boring-tls` integration can silently disable TLS hostname verification, allowing an on-path attacker to intercept SMTP submissions, including credentials and message content, against users of the `boring-tls` feature. This could expose sensitive communication data.

CVE advisoryCRITICAL

CVE-2026-46412

`@beproduct/nestjs-auth` Malicious Package Steals npm GitHub AWS and Vault Secrets.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A compromised authentication module, `@beproduct/nestjs-auth`, was published with malicious versions that harvested secrets like npm, GitHub, and AWS credentials during installation. If reachable or relevant, this could lead to the exposure of sensitive tokens and credentials used in development and build processes. Th

CVE advisoryCRITICAL

CVE-2026-35198

HeyForm Stored Cross-Site Scripting Vulnerability Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability in HeyForm's form builder may permit a low-privileged user to inject malicious JavaScript that executes when a team owner views the form. This could lead to account takeover through privilege escalation, impacting the confidentiality, integrity, and availability of the compro

CVE advisoryCRITICAL

CVE-2026-28220

Wazuh Cluster API Vulnerability Allows Master Node Takeover.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Wazuh's Cluster Distributed API has a vulnerability that could allow an authenticated actor to execute arbitrary code on the master node, potentially leading to administrative control. This issue could impact system data and sensitive information if the cluster channel is reachable and the shared cluster key is comprom

CVE advisoryCRITICAL

CVE-2026-63071

Apache Syncope Groovy Sandbox Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An Improper Isolation vulnerability in Apache Syncope allows an administrator to bypass the Groovy security sandbox by creating a malicious Groovy class, potentially enabling untrusted code execution. This issue affects specific versions of Apache Syncope, and users are advised to upgrade to patched versions.

CVE advisoryCRITICAL

CVE-2026-62183

Apache Syncope Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper privilege management vulnerability exists in Apache Syncope, potentially allowing unauthenticated users to gain administrative access. This occurs when specific user workflow adapters are misconfigured, enabling a user to grant themselves roles via a REST API call, thereby acquiring administrative entitleme

CVE advisoryCRITICAL

CVE-2026-57308

Apache Syncope SQL Injection via Unsantized Sort Parameters

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability exists in Apache Syncope, allowing privileged administrators to execute arbitrary SQL commands by exploiting unsanitized sort parameters. This could impact systems managing identity and access, potentially leading to unauthorized data manipulation or access. Confirmation of affect

CVE advisoryCRITICAL

CVE-2026-53421

Apache Syncope RCE via Scripted Connectors

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Syncope allows for remote code execution by administrators through its connector subsystem. This can happen when an administrator uses scripted connectors, such as REST and SQL, to run Groovy scripts, potentially leading to unauthorized system control.

CVE advisoryCRITICAL

CVE-2026-53405

Apache Syncope Groovy Script Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Apache Syncope allows an administrator with entitlements to import and start BPMN processes containing Groovy scripts, which execute directly on the server without sandboxing, potentially leading to arbitrary code execution. This issue affects specific versions and requires administrative access and

CVE advisoryCRITICAL

CVE-2026-12701

pulpcore Path Traversal Leads to Arbitrary File Write

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability in pulpcore allows an authenticated administrator to write arbitrary files to any location writable by the service user. This can be exploited during FilesystemExport operations by crafting malicious relative paths, potentially leading to service compromise or system exploitation. The vul

CVE advisoryCRITICAL

CVE-2026-57309

Windu CMS Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Blind SQL injection vulnerability exists in Windu CMS, allowing unauthenticated attackers to inject SQL syntax via HTTP headers, potentially enabling unauthorized database access. The vulnerability is confirmed in version 4.1, but may affect others, and vendor contact has been unsuccessful.

CVE advisoryCRITICAL

CVE-2026-64622

Network-AI ApprovalInbox Unauthorized Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Network-AI allows unauthenticated actors to access sensitive approval request details by failing to apply configured authorization checks to certain network routes. This could expose operational information, including command strings and file paths, to unauthorized parties.

CVE advisoryCRITICAL

CVE-2026-64621

FreeRDP SelectedMonitors Double-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A double-free vulnerability exists in FreeRDP clients when processing crafted `.rdp` files. Opening such a file could lead to controlled memory corruption, potentially impacting application stability. The relevance depends on whether your organization uses FreeRDP clients and if users might be tricked into opening mali

CVE advisoryCRITICAL

CVE-2026-64620

FreeRDP Heap-Based Buffer Overflow Denial of Service

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap-based buffer overflow in FreeRDP's RSA decryption can allow an unauthenticated attacker to cause a denial of service when RDP Standard Security is used. This vulnerability is reachable over the network without authentication, posing a risk to systems that expose RDP services.

CVE advisoryCRITICAL

CVE-2026-63756

SurrealDB RPC Session Race Condition Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A race condition in SurrealDB's HTTP /rpc endpoint allows unauthenticated attackers to inherit authenticated session states and execute operations with hijacked user privileges. This vulnerability is reachable via network access and exploits a timing flaw in concurrent requests, potentially leading to unauthorized acti

CVE advisoryCRITICAL

CVE-2026-16242

Konnectivity Proxy unauthenticated agent access and traffic manipulation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in Konnectivity proxy-server configuration allows unauthenticated remote attackers to impersonate agents, potentially enabling them to proxy, inspect, modify, or drop control-plane-to-node traffic. This matters because it could compromise the integrity and confidentiality of critical cluster communications. The

CVE advisoryCRITICAL

CVE-2026-16235

Crypt::Password Insecure Salt Generation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Crypt::Password for Perl allows for predictable generation of security salts, potentially weakening password security. This could impact applications using the library, allowing attackers to compromise password hashing and potentially gain unauthorized access to user accounts. The relevance and expos

CVE advisoryCRITICAL

CVE-2026-13147

Kirki WordPress Plugin Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Kirki WordPress plugin has a Server-Side Request Forgery vulnerability that allows unauthenticated attackers to cause the site to issue HTTP requests to arbitrary hosts. This could potentially lead to unauthorized access or manipulation of web infrastructure by tricking the site into sending requests to external se

CVE advisoryCRITICAL

CVE-2026-44359

Meshtastic Workflow Compromise Via Forked Pull Requests

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Meshtastic's development workflow could allow an attacker to execute arbitrary code with elevated permissions by submitting a pull request, potentially leading to supply chain compromise or repository takeover. The issue arises because the workflow checks out and executes code from an attacker's fork