NVD disclosure day

Published threat advisories for July 21, 2026

CVE advisoryCRITICAL

CVE-2026-65048

Ninja Forms Unauthenticated Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated stored cross-site scripting vulnerability in the Ninja Forms plugin for WordPress allows attackers to inject malicious scripts via form submissions. These scripts can execute in an administrator's browser when viewing submissions, potentially leading to session theft or unauthorized site modification

CVE advisoryCRITICAL

CVE-2026-65008

Grav Blueprint DynamicData Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Grav CMS has a remote code execution vulnerability in Blueprint::dynamicData() that could allow an authenticated user to plant a malicious directive in a page. Accessing that page, even by unauthenticated visitors, would execute the command as the web server user, potentially impacting the integrity and availability of

CVE advisoryCRITICAL

CVE-2026-1617

Turkhotspot 5651 Loglama SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical SQL injection vulnerability exists in Turkmesh Turkhotspot 5651 Loglama, allowing unauthenticated attackers to manipulate database commands over the network. This could lead to unauthorized access, modification, or disclosure of sensitive information. Confirmation of product usage within the environment is n

CVE advisoryCRITICAL

CVE-2026-64606

Apache Fory Lambda Deserialization Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A deserialization vulnerability in Apache Fory allows bypassing Java lambda deserialization checks, potentially impacting lambda capture classes. This could lead to unauthorized actions if the vulnerable component processes untrusted data. Assess its relevance in your environment.

CVE advisoryCRITICAL

CVE-2026-64608

Apache Fory C++ Deserialization Type Confusion Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap type confusion vulnerability exists in the C++ implementation of Apache Fory, a data serialization library. This flaw allows for out-of-bounds memory access when processing inconsistent data schemas during deserialization. It may impact the confidentiality, integrity, and availability of systems using this speci

CVE advisoryCRITICAL

CVE-2026-13439

Easy Form Builder WordPress Plugin Unauthenticated Administrator Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Easy Form Builder WordPress plugin has a critical vulnerability allowing unauthenticated users to escalate privileges to administrator. This is possible by exploiting the password recovery flow to reset any user's password and gain full administrative control of the WordPress site.