NVD disclosure day

Published threat advisories for July 20, 2026

CVE advisoryCRITICAL

CVE-2026-63766

GPT-SoVITS OS Command Injection via Web UI

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in GPT-SoVITS's web UI where unsanitized user input is directly used in shell commands. This could allow unauthenticated attackers to execute arbitrary OS commands on the server. Confirming if this technology is in use is crucial to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-61900

Joomla JDownloads Unauthenticated File Upload Leading to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Joomla extension JDownloads has a critical vulnerability allowing unauthenticated file uploads. This could enable remote code execution on affected systems. Attackers can exploit this by uploading malicious files, potentially compromising the integrity and availability of the web application. Confirming its presenc

CVE advisoryCRITICAL

CVE-2026-61424

DJ-Classifieds Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the DJ-Classifieds Joomla extension that allows unauthenticated attackers to upload files and achieve remote code execution. This issue could enable an attacker to gain complete control of a server if the extension is present and reachable. Organizations should confirm if DJ-Classifie

CVE advisoryCRITICAL

CVE-2026-60032

Joomla JMedia Arbitrary File Upload Leading to RCE

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Joomla JMedia extension permits authenticated users to upload and execute arbitrary files, potentially leading to remote code execution on the server. This means an attacker who has already gained administrative access to the Joomla interface could exploit this flaw to control the server, making

CVE advisoryCRITICAL

CVE-2026-39878

Chamilo LMS Stored XSS in Registration Form Allows Admin Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in the Chamilo LMS user registration form. This allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser, potentially leading to full admin account takeover and platform control.

CVE advisoryCRITICAL

CVE-2026-54051

Network-AI Command Injection via Shell Metacharacters in Allowlist Bypass.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Network-AI, a multi-agent orchestrator, where broad wildcard allowlist entries can be bypassed to execute arbitrary shell commands. This occurs because the system's shell processing can misinterpret commands, allowing unintended execution if an attacker gains control of an agent.

CVE advisoryCRITICAL

CVE-2026-41252

xrdp vnc-any Heap Overflow Leads to Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker in control of a VNC server can exploit a heap-based buffer overflow in xrdp's vnc-any mode by sending crafted color map messages. This memory corruption can lead to denial of service or remote code execution. The vulnerability's impact depends on whether xrdp is used in this specific mode an

CVE advisoryCRITICAL

CVE-2026-35048

Piwigo Installer Arbitrary Code Execution via Unsanitized POST Parameters

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Piwigo installer allows unauthenticated attackers to execute arbitrary PHP code by sending crafted POST parameters, which are written to a configuration file without proper sanitization, especially on PHP 8+. This could lead to the compromise of the Piwigo application.

CVE advisoryCRITICAL

CVE-2026-51027

FileThingie ft2.php Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in FileThingie's ft2.php component could allow a remote attacker to obtain sensitive information. This issue may impact data confidentiality and integrity if the component is reachable. Readers should confirm FileThingie's presence and exposure in their environment.

CVE advisoryCRITICAL

CVE-2026-46428

Lettre Boring-TLS Disables Hostname Verification

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the `lettre` Rust email library's `boring-tls` integration can silently disable TLS hostname verification, allowing an on-path attacker to intercept SMTP submissions, including credentials and message content, against users of the `boring-tls` feature. This could expose sensitive communication data.

CVE advisoryCRITICAL

CVE-2026-46412

`@beproduct/nestjs-auth` Malicious Package Steals npm GitHub AWS and Vault Secrets.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A compromised authentication module, `@beproduct/nestjs-auth`, was published with malicious versions that harvested secrets like npm, GitHub, and AWS credentials during installation. If reachable or relevant, this could lead to the exposure of sensitive tokens and credentials used in development and build processes. Th

CVE advisoryCRITICAL

CVE-2026-35198

HeyForm Stored Cross-Site Scripting Vulnerability Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability in HeyForm's form builder may permit a low-privileged user to inject malicious JavaScript that executes when a team owner views the form. This could lead to account takeover through privilege escalation, impacting the confidentiality, integrity, and availability of the compro

CVE advisoryCRITICAL

CVE-2026-12701

pulpcore Path Traversal Leads to Arbitrary File Write

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability in pulpcore allows an authenticated administrator to write arbitrary files to any location writable by the service user. This can be exploited during FilesystemExport operations by crafting malicious relative paths, potentially leading to service compromise or system exploitation. The vul

CVE advisoryCRITICAL

CVE-2026-57309

Windu CMS Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Blind SQL injection vulnerability exists in Windu CMS, allowing unauthenticated attackers to inject SQL syntax via HTTP headers, potentially enabling unauthorized database access. The vulnerability is confirmed in version 4.1, but may affect others, and vendor contact has been unsuccessful.

CVE advisoryCRITICAL

CVE-2026-64622

Network-AI ApprovalInbox Unauthorized Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Network-AI allows unauthenticated actors to access sensitive approval request details by failing to apply configured authorization checks to certain network routes. This could expose operational information, including command strings and file paths, to unauthorized parties.

CVE advisoryCRITICAL

CVE-2026-64621

FreeRDP SelectedMonitors Double-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A double-free vulnerability exists in FreeRDP clients when processing crafted `.rdp` files. Opening such a file could lead to controlled memory corruption, potentially impacting application stability. The relevance depends on whether your organization uses FreeRDP clients and if users might be tricked into opening mali

CVE advisoryCRITICAL

CVE-2026-64620

FreeRDP Heap-Based Buffer Overflow Denial of Service

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap-based buffer overflow in FreeRDP's RSA decryption can allow an unauthenticated attacker to cause a denial of service when RDP Standard Security is used. This vulnerability is reachable over the network without authentication, posing a risk to systems that expose RDP services.

CVE advisoryCRITICAL

CVE-2026-63756

SurrealDB RPC Session Race Condition Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A race condition in SurrealDB's HTTP /rpc endpoint allows unauthenticated attackers to inherit authenticated session states and execute operations with hijacked user privileges. This vulnerability is reachable via network access and exploits a timing flaw in concurrent requests, potentially leading to unauthorized acti

CVE advisoryCRITICAL

CVE-2026-16242

Konnectivity Proxy unauthenticated agent access and traffic manipulation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in Konnectivity proxy-server configuration allows unauthenticated remote attackers to impersonate agents, potentially enabling them to proxy, inspect, modify, or drop control-plane-to-node traffic. This matters because it could compromise the integrity and confidentiality of critical cluster communications. The

CVE advisoryCRITICAL

CVE-2026-16235

Crypt::Password Insecure Salt Generation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Crypt::Password for Perl allows for predictable generation of security salts, potentially weakening password security. This could impact applications using the library, allowing attackers to compromise password hashing and potentially gain unauthorized access to user accounts. The relevance and expos

CVE advisoryCRITICAL

CVE-2026-13147

Kirki WordPress Plugin Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Kirki WordPress plugin has a Server-Side Request Forgery vulnerability that allows unauthenticated attackers to cause the site to issue HTTP requests to arbitrary hosts. This could potentially lead to unauthorized access or manipulation of web infrastructure by tricking the site into sending requests to external se

CVE advisoryCRITICAL

CVE-2026-44359

Meshtastic Workflow Compromise Via Forked Pull Requests

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Meshtastic's development workflow could allow an attacker to execute arbitrary code with elevated permissions by submitting a pull request, potentially leading to supply chain compromise or repository takeover. The issue arises because the workflow checks out and executes code from an attacker's fork