NVD disclosure day

Published threat advisories for July 21, 2026

CVE advisoryCRITICAL

CVE-2026-56820

Netty OcspClient Bypass Revocation Checks Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Netty's `OcspClient` could allow a replay attack, bypassing certificate revocation checks. This occurs when a signed OCSP response for an unrelated certificate is accepted as valid for a different certificate, potentially allowing the use of revoked certificates. Uncertainty exists regarding the spec

CVE advisoryCRITICAL

CVE-2026-16419

Chrome for Android ANGLE Sandbox Escape Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ANGLE, used by Google Chrome on Android, allows remote attackers to escape the browser sandbox via a crafted HTML page. This could lead to broader system compromise if users access malicious websites. It is uncertain which specific Chrome versions are affected.

CVE advisoryCRITICAL

CVE-2026-8987

Autel Maxi Charger Heap Overflow Denial of Service and Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Autel Maxi Charger Single firmware has a heap-based buffer overflow vulnerability that an authenticated attacker could exploit via the `/localcfg` endpoint to cause denial of service or potentially execute arbitrary code. Confirmation is needed to determine if this technology is in use and its potential reachability.

CVE advisoryCRITICAL

CVE-2026-8985

Autel Maxi Charger OS Command Injection.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can inject arbitrary operating system commands into Autel Maxi Charger firmware via the `/test` endpoint on TCP port 9002. This vulnerability could allow unauthorized control or disruption of charging infrastructure if the affected device is network-accessible.

CVE advisoryCRITICAL

CVE-2026-8984

Autel Maxi Charger Remote Code Execution via Unauthenticated TCP Service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Autel Maxi Charger Single firmware, allowing unauthenticated remote code execution via a service on TCP port 9002. Exploitation requires a crafted request to the `/test` endpoint, enabling an attacker to download and run arbitrary files with root privileges, posing a risk to network-c

CVE advisoryCRITICAL

CVE-2026-65318

Verba SSRF via WebSocket Import Endpoint.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated server-side request forgery vulnerability exists in the Verba RAG application, allowing attackers to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through its WebSocket import endpoint. This could enable attackers to access sensitive internal resources, such as database endp

CVE advisoryCRITICAL

CVE-2026-65317

Verba RAG SSRF and Middleware Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability exists in Verba RAG applications, allowing unauthenticated attackers to make the server issue arbitrary HTTP requests. By manipulating specific headers, attackers can bypass origin checks and send requests to attacker-controlled infrastructure, potentially interacting with in

CVE advisoryCRITICAL

CVE-2026-61245

Oracle PeopleSoft Enterprise FIN Manufacturing Brazil Integration Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft's Enterprise FIN Manufacturing Brazil integration component allows unauthenticated network attackers to achieve full system takeover. This easily exploitable flaw, with a CVSS score of 9.8, impacts confidentiality, integrity, and availability, making it a significant concer

CVE advisoryCRITICAL

CVE-2026-61244

Oracle PeopleSoft Manufacturing Argentina Data Compromise Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle PeopleSoft's Manufacturing Argentina product allows unauthenticated attackers with network access to compromise the system. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, or complete access to all accessible data, impacting confidential

CVE advisoryCRITICAL

CVE-2026-61242

Oracle PeopleSoft FIN Common Objects Argentina Staffing Vulnerability Allows Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle PeopleSoft's FIN Common Objects Argentina, specifically its Staffing component, allowing a low-privileged attacker with network access to potentially take over the system and impact other connected products. While direct internet exposure is unlikely, this could lead to signifi

CVE advisoryCRITICAL

CVE-2026-61239

Oracle PeopleSoft eProcurement Critical Data Tampering and Denial of Service Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft's eProcurement allows unauthenticated network attackers to modify, delete, or read critical data and cause a partial denial of service. This easily exploitable issue could impact additional products beyond the directly affected component.

CVE advisoryCRITICAL

CVE-2026-61238

PeopleSoft eProcurement Argentina Data Integrity and Confidentiality Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle PeopleSoft's eProcurement component, specifically concerning common objects for Argentina. This issue allows unauthenticated network attackers to access, modify, or delete critical data, or gain complete access to all accessible information. The vulnerability's ease of exploita

CVE advisoryCRITICAL

CVE-2026-61237

Oracle PeopleSoft FIN Common Objects Argentina Vulnerability Allows Unauthorized Data Access and Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Argentina allows unauthenticated attackers to access or modify data and cause a partial denial of service. The attack is exploitable over the network and may impact additional products.

CVE advisoryCRITICAL

CVE-2026-61235

Oracle PeopleSoft Global Payroll Switzerland Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft's Global Payroll for Switzerland component can be exploited by a highly privileged attacker with network access. Successful exploitation could lead to a takeover of the affected PeopleSoft system and potentially impact other connected products.

CVE advisoryCRITICAL

CVE-2026-61233

Oracle PeopleSoft FIN Brazil Integration Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle PeopleSoft Enterprise FIN Common Objects Brazil's integration component, allowing unauthenticated network access to achieve system takeover. This affects confidentiality, integrity, and availability. You should care because a successful attack could lead to complete compromise

CVE advisoryCRITICAL

CVE-2026-61223

Oracle Communications Converged Application Server Security Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Communications Converged Application Server could allow an unauthenticated attacker with network access to take control of the server, potentially impacting other products. Because this is a critical security flaw, organizations should determine if they use this product and if it is exposed to

CVE advisoryCRITICAL

CVE-2026-61211

Oracle Database RDBMS Takeover Vulnerability with CVSS 9.9

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Database Server's RDBMS component allows a low-privileged attacker with network access to potentially take over the database. Successful exploitation could impact other integrated products and lead to a complete loss of confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-61209

Oracle PeopleSoft In-Memory Project Discovery Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle PeopleSoft's In-Memory Project Discovery product. An attacker with low privileges and network access can exploit this to take over the Project Discovery component, potentially impacting other PeopleSoft products.

CVE advisoryCRITICAL

CVE-2026-61207

Oracle PeopleSoft eProcurement Unauthorized Data Access and Modification Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Oracle's PeopleSoft Enterprise SCM eProcurement product, allowing unauthenticated attackers network access to compromise the system. This could result in unauthorized access to or modification of critical data, with potential impact to other connected PeopleSoft products.

CVE advisoryCRITICAL

CVE-2026-61204

Oracle PeopleSoft FIN Program Management Primavera Integration Vulnerability Enables Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle PeopleSoft's Program Management product, specifically its Primavera integration, allows a low-privileged attacker with network access to compromise the system if a user interacts with malicious content. Successful exploitation could lead to a complete takeover of the affected PeopleSoft system

CVE advisoryCRITICAL

CVE-2026-61203

Oracle PeopleSoft FIN Expenses Critical Data Exposure and Modification Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle PeopleSoft Enterprise FIN Expenses allows unauthenticated attackers with network access to modify or delete critical data, gain unauthorized access to data, or cause a partial denial of service. This issue is reachable via HTTP and poses a significant risk to data confidentiality, integrity, a

CVE advisoryCRITICAL

CVE-2026-61197

Oracle Identity Manager Legacy UI Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Identity Manager, an Oracle Fusion Middleware product, allowing unauthenticated attackers with network access to compromise the system. Successful exploitation could lead to unauthorized access, modification, or deletion of critical data, impacting identity and access managemen

CVE advisoryCRITICAL

CVE-2026-61196

Oracle Identity Manager OIM Legacy UI Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Identity Manager's legacy UI allows unauthenticated network attackers to achieve a complete system takeover. This issue could impact the confidentiality, integrity, and availability of identity management functions.

CVE advisoryCRITICAL

CVE-2026-61186

Oracle Agile Engineering Data Management Install Vulnerability Allows Data Tampering and Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated network attacker can exploit a vulnerability in Oracle Agile Engineering Data Management's Install component to gain unauthorized access to critical data, modify or delete it, or cause a denial of service. This could impact the confidentiality, integrity, and availability of sensitive engineering and

CVE advisoryCRITICAL

CVE-2026-61184

Oracle Agile PLM for Process Product Quality Management Unauthorized Data Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Agile Product Lifecycle Management for Process. This could lead to unauthorized creation, deletion, or modification of critical data, or complete unauthorized access to all accessible data. This affects supply chain product management

CVE advisoryCRITICAL

CVE-2026-61183

Oracle Agile PLM for Process Reporting Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Agile Product Lifecycle Management for Process, part of Oracle Supply Chain, allows unauthenticated attackers with network access to take over the system. This could impact data confidentiality, integrity, and availability, making it a significant concern for affected organizations.

CVE advisoryCRITICAL

CVE-2026-61175

Oracle Product Lifecycle Analytics Installation Issues Vulnerability Allows Critical Data Access and Partial Denial of Service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated network attacker can exploit a vulnerability in Oracle Product Lifecycle Analytics, potentially leading to unauthorized access to critical data and a partial denial of service. While the vulnerability is in Oracle Product Lifecycle Analytics, its impact may extend to other connected products.

CVE advisoryCRITICAL

CVE-2026-61171

Oracle Agile PLM Security Vulnerability Allows Unauthorized Data Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Agile PLM allows unauthenticated network attackers to modify or access sensitive product lifecycle data. This issue, with a high impact on data confidentiality and integrity, necessitates verifying if Oracle Agile PLM is in use and exposed to prevent unauthorized data compromise.

CVE advisoryCRITICAL

CVE-2026-61156

Oracle Commerce Guided Search Forge Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Commerce Guided Search Platform Services allows unauthenticated network attackers to gain unauthorized access, modification, or deletion of critical data. This issue affects the Forge component and could lead to significant data compromise if reachable via HTTPS.

CVE advisoryCRITICAL

CVE-2026-61155

Oracle Commerce Guided Search Platform Services Forge Vulnerability Allows Unauthorized Data Access and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search Platform Services, allowing unauthenticated network attackers to access critical data or cause service disruptions. This issue, rated CRITICAL with a CVSS score of 9.1, impacts the confidentiality and availability of the platform.

CVE advisoryCRITICAL

CVE-2026-61154

Oracle Commerce Guided Search Platform Services Forge Vulnerability Allows Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Commerce Guided Search Platform Services allows an unauthenticated attacker with network access to take over the affected services. This could compromise confidentiality, integrity, and availability, making it important to confirm the relevance and exposure of this vulnerability withi

CVE advisoryCRITICAL

CVE-2026-61153

Oracle Commerce Guided Search Experience Manager Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Commerce Guided Search and Experience Manager allows unauthenticated attackers with network access to compromise the system. Successful exploitation could lead to unauthorized modification or deletion of critical data, or complete access to all accessible data. This issue is relevant

CVE advisoryCRITICAL

CVE-2026-61146

Oracle Commerce Guided Search Content Acquisition System Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Commerce's Content Acquisition System, allowing low-privileged attackers with network access to achieve complete system takeover. This compromise of Oracle Commerce Guided Search and Experience Manager could significantly impact additional products.

CVE advisoryCRITICAL

CVE-2026-61145

Oracle Commerce Guided Search Content Acquisition System Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search and Experience Manager products, allowing unauthenticated attackers with network access to potentially take over the affected systems. This could impact data confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-61130

Oracle Commerce Platform Remote Data Exposure and Denial of Service Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Oracle Commerce Platform allows unauthenticated attackers to access critical data or cause a denial of service. This issue affects the Dynamo Application Framework component and is reachable via HTTP. Successful exploitation could result in unauthorized access to sensitive data or complete servic

CVE advisoryCRITICAL

CVE-2026-61129

Oracle Commerce Platform ATG Portals Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Commerce Platform's ATG Portals component allows unauthenticated network attackers to achieve complete platform takeover. This issue impacts confidentiality, integrity, and availability, necessitating an immediate assessment of organizational use and exposure.

CVE advisoryCRITICAL

CVE-2026-61100

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture that an unauthenticated attacker with network access could exploit to gain complete control of the system. This poses a significant risk to confidentiality, integrity, and availability. It is important to determine if this technology is used within

CVE advisoryCRITICAL

CVE-2026-61097

Oracle Banking Trade Finance Process Management Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Banking Trade Finance Process Management could allow an unauthenticated attacker to access, modify, or delete critical data, or cause a partial denial of service. Successful exploitation requires network access and user interaction, and may impact other products.

CVE advisoryCRITICAL

CVE-2026-61076

Oracle PeopleSoft Job Opening Takeover Vulnerability CVE-2026-61076

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager's Job Opening component allows a low-privileged attacker with network access to potentially take over the system. This exploitation could impact additional products and compromise confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-61072

Oracle PeopleSoft Staffing Brazil Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft's Staffing Front Office Brazil product allows a low-privileged attacker with network access to compromise the system, potentially impacting other products. This could result in a complete takeover of the affected application, affecting confidentiality, integrity, and availa

CVE advisoryCRITICAL

CVE-2026-61065

Oracle Access Manager Authentication Engine Vulnerability Allows Full Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access to take over the system. This could impact authentication services and potentially lead to unauthorized access.

CVE advisoryCRITICAL

CVE-2026-61059

Oracle PeopleSoft Order Management Remote Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle PeopleSoft Enterprise SCM Order Management, allowing unauthenticated attackers network access via HTTP to compromise the system. This could lead to unauthorized creation, deletion, or modification of critical data, or complete unauthorized access to all accessible data. The iss

CVE advisoryCRITICAL

CVE-2026-60880

Oracle E-Business Suite Work in Process Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Work in Process (part of Oracle E-Business Suite) allows unauthenticated network attackers to potentially take over the application. This issue impacts the confidentiality, integrity, and availability of the affected system, necessitating a review to determine if this component is in

CVE advisoryCRITICAL

CVE-2026-60773

Oracle E-Business Suite Application Object Library Vulnerability Allows Unauthorized Data Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Application Object Library, part of Oracle E-Business Suite, allows a low-privileged attacker with network access to compromise the system. Successful exploitation could result in unauthorized modification or access to critical data, potentially impacting other connected products.

CVE advisoryCRITICAL

CVE-2026-60719

Oracle BI Publisher Web Service API Vulnerability Allows Critical Data Manipulation and Denial of Service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle BI Publisher's Web Service API, potentially allowing a low-privileged attacker with network access to modify or access critical data and cause a partial denial of service, with possible impact on connected products.

CVE advisoryCRITICAL

CVE-2026-60711

Oracle Siebel CRM Cloud Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component allows a low-privileged attacker with network access to take over the applications. Exploitation could significantly impact other products. The issue poses high risks to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60663

Oracle WebCenter Content Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker with network access to take over the system, potentially impacting other products. This issue affects confidentiality, integrity, and availability of the content management system.

CVE advisoryCRITICAL

CVE-2026-60649

Oracle WebCenter Content Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle WebCenter Content allows unauthenticated attackers with network access to gain unauthorized access to or modify critical data. This could result in the compromise of sensitive information managed by the product.

CVE advisoryCRITICAL

CVE-2026-60644

Oracle WebCenter Content Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Content that allows unauthenticated attackers with network access to compromise the system, potentially affecting other products. Successful exploitation could lead to a complete takeover of Oracle WebCenter Content, impacting its confidentiality, integrity, and avail

CVE advisoryCRITICAL

CVE-2026-60632

Oracle WebCenter Content HTTP Remote Data Tampering and Theft Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Content may allow an unauthenticated attacker with network access to compromise the system. This vulnerability requires user interaction and could lead to unauthorized modification, deletion, or access to critical data within WebCenter Content, potentially impacting other pr

CVE advisoryCRITICAL

CVE-2026-60631

Oracle WebCenter Content Server Unauthorized Data Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access to compromise the product. Exploitation requires user interaction and could lead to unauthorized modification or access of critical data, potentially impacting other products. This issue warrants attention to confirm if t

CVE advisoryCRITICAL

CVE-2026-60627

Oracle JD Edwards EnterpriseOne Tools Installation Security Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, specifically in its installation security component. This easily exploitable flaw allows a low-privileged attacker with network access to achieve a complete takeover of the tool, potentially impacting other connected products. This issue is reach

CVE advisoryCRITICAL

CVE-2026-60606

Oracle PeopleSoft Common Application Objects Data Tampering Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects allows unauthenticated attackers with network access to compromise critical data, leading to unauthorized creation, deletion, or modification. This could result in unauthorized access to or complete control over accessible data within the Peo

CVE advisoryCRITICAL

CVE-2026-60568

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal allows a low-privileged attacker with network access to compromise the application, potentially leading to a complete takeover and impacting other products. This issue affects the confidentiality, integrity, and availability of the affected systems.

CVE advisoryCRITICAL

CVE-2026-60567

Oracle Identity Manager Legacy UI Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Oracle Identity Manager's Legacy UI allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data.

CVE advisoryCRITICAL

CVE-2026-60565

Oracle WebCenter Portal Runtime Tools Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle WebCenter Portal allows a low-privileged attacker with network access to take over the system, potentially impacting other products. This critical issue poses a significant risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60564

Oracle WebCenter Portal Runtime Tools Data Corruption and Unauthorized Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal's Runtime Tools allows a low-privileged attacker with network access via HTTP to compromise the system. This could lead to unauthorized modification or deletion of critical data, or complete access to all accessible data, potentially impacting other Oracle Fusion Midd

CVE advisoryCRITICAL

CVE-2026-60562

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal that an attacker with network access and low privileges can exploit. Successful exploitation allows for a complete takeover of the affected portal and may impact other connected products. This poses a significant risk to confidentiality, integrity, and availabi

CVE advisoryCRITICAL

CVE-2026-60555

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows unauthenticated network attackers to compromise the product, potentially leading to a complete system takeover. This issue affects the confidentiality, integrity, and availability of the affected Oracle WebCenter Sites instances. Confirming organizational use of

CVE advisoryCRITICAL

CVE-2026-60552

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows a low-privileged attacker with network access to achieve a full takeover of the system, potentially impacting other connected products. This issue presents significant risks to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60551

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access to compromise the system, potentially leading to a full takeover. This could impact the confidentiality, integrity, and availability of web content managed by the product, making it important to assess if this tech

CVE advisoryCRITICAL

CVE-2026-60547

Oracle Managed File Transfer MFT Runtime Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Managed File Transfer's MFT Runtime Server, allowing a low-privileged attacker with network access to compromise the service. Successful exploitation can lead to a takeover of the file transfer system and potentially impact additional connected products.

CVE advisoryCRITICAL

CVE-2026-60542

Oracle Business Process Management Suite Workflow Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Business Process Management Suite's Human Workflow component, allowing a low-privileged attacker with network access to take over the system and potentially impact other products. This could result in significant confidentiality, integrity, and availability impacts.

CVE advisoryCRITICAL

CVE-2026-60541

Oracle SOA Suite Enterprise Scheduling System Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle SOA Suite that allows unauthenticated network attackers to compromise the system, potentially leading to a complete takeover. This issue impacts confidentiality, integrity, and availability, making it crucial to assess system exposure and business criticality for prioritization

CVE advisoryCRITICAL

CVE-2026-60538

Oracle SOA Suite Enterprise Scheduling System Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle SOA Suite's Enterprise Scheduling System allows unauthenticated network access, potentially leading to a complete system takeover and impacting confidentiality, integrity, and availability. This issue warrants attention to confirm if the technology is in use and exposed within the env

CVE advisoryCRITICAL

CVE-2026-60537

Oracle Managed File Transfer Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Managed File Transfer could allow a low-privileged attacker with network access to take over the system, potentially impacting other products. This issue in Oracle Fusion Middleware's MFT Runtime Server poses significant risks to data confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60531

Oracle Identity Manager Connector Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware, allowing a low-privileged attacker with network access to take control of the connector. This could significantly impact additional products, leading to severe consequences for confidentiality, integrity, and

CVE advisoryCRITICAL

CVE-2026-60524

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware. Attackers with low privileges and network access could potentially take over the affected system, impacting additional products. This could result in complete takeover of Oracle WebCenter Enterprise Capture,

CVE advisoryCRITICAL

CVE-2026-60463

Oracle WebCenter Content Imaging Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle WebCenter Content: Imaging, allowing unauthenticated network attackers to achieve a complete system takeover. This issue, impacting confidentiality, integrity, and availability, warrants confirmation of product usage and assessment of potential exposure.

CVE advisoryCRITICAL

CVE-2026-60461

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, could enable a low-privileged attacker with network access to gain complete control over the system, potentially affecting other products. This could lead to unauthorized access to business data and impact document proces

CVE advisoryCRITICAL

CVE-2026-60460

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture may allow an unauthenticated attacker with network access to take over the system. This means an attacker could gain full control, impacting confidentiality, integrity, and availability. Confirm relevance and exposure within your Oracle WebCenter Enterpris

CVE advisoryCRITICAL

CVE-2026-60459

Oracle WebCenter Enterprise Capture Takeover via Network Attack

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture could allow a low-privileged attacker with network access to take over the system, potentially impacting other connected products. This easily exploitable flaw, reachable via HTTP, requires confirmation of its presence and exposure within your environment.

CVE advisoryCRITICAL

CVE-2026-60458

Oracle WebCenter Enterprise Capture Critical Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture could allow a low-privileged attacker with network access to take over the product, potentially impacting other systems. This issue presents significant risks to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60457

Oracle WebCenter Enterprise Capture T3 IIOP Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, allows a low-privileged attacker with network access to take over the system. This compromise can significantly impact additional products. The vulnerability is reachable via T3 or IIOP protocols.

CVE advisoryCRITICAL

CVE-2026-60456

Oracle WebCenter Enterprise Capture Critical Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, that could allow a low-privileged attacker with network access to take control of the system, potentially impacting other products. This could lead to significant confidentiality, integrity, and availability

CVE advisoryCRITICAL

CVE-2026-60446

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, allowing an unauthenticated network attacker to potentially gain full control of the product. This could impact data confidentiality, integrity, and availability, making it important to confirm if this technology is in use and assess its exposure.

CVE advisoryCRITICAL

CVE-2026-60445

Oracle WebCenter Enterprise Capture Takeover via Network Attack

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged attacker with network access to compromise the system, potentially impacting additional products. Successful exploitation can lead to a complete takeover, posing a significant risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60442

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows unauthenticated attackers with network access to take over the platform, impacting confidentiality, integrity, and availability. This issue warrants attention due to its potential for complete system compromise.

CVE advisoryCRITICAL

CVE-2026-60441

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform, allowing unauthenticated network attackers to achieve complete takeover. This impacts the platform's confidentiality, integrity, and availability. Readers should care because it affects critical middleware infrastructure.

CVE advisoryCRITICAL

CVE-2026-60438

Oracle HTTP Server mod_ssl Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle HTTP Server's mod_ssl component allows unauthenticated network attackers to gain unauthorized access to, modify, or delete critical data. This could lead to a complete compromise of data accessible by the server.

CVE advisoryCRITICAL

CVE-2026-60435

Oracle WebCenter Content Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Content, allowing unauthenticated attackers with network access to take over the system. This means an attacker could gain complete control without needing any credentials, posing a risk to content integrity and availability. Organizations should determine if they use

CVE advisoryCRITICAL

CVE-2026-60424

Oracle Unified Directory LDAP Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Unified Directory allows an unauthenticated attacker with network access via LDAP to take over the directory. Successful exploitation could lead to a complete compromise of the directory service and potentially impact other connected products, affecting confidentiality, integrity, and

CVE advisoryCRITICAL

CVE-2026-60422

Oracle Unified Directory LDAP Remote Code Execution and Data Corruption.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Unified Directory, potentially allowing a low-privileged attacker with network access via LDAP to compromise the service. This could lead to unauthorized access, modification, or deletion of critical data, and a partial denial of service, with possible impacts to other products

CVE advisoryCRITICAL

CVE-2026-60402

Oracle TimesTen Kubernetes Operator Critical Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle TimesTen's Kubernetes Operator that a low-privileged attacker with network access can exploit. This could lead to a complete takeover of the TimesTen In-Memory Database and potentially impact other connected products due to the operator's scope.

CVE advisoryCRITICAL

CVE-2026-60389

Oracle Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated network attacker can exploit a vulnerability in Oracle Fusion Middleware's Service Delivery Platform via HTTP. Successful exploitation could lead to a takeover of the platform, with potential impacts on other connected products. This issue is rated Critical due to its severe effects on confidentialit

CVE advisoryCRITICAL

CVE-2026-60387

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform, allowing unauthenticated attackers with network access to completely take over the system. This could impact the availability and integrity of services managed by the platform.

CVE advisoryCRITICAL

CVE-2026-60386

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows unauthenticated network attackers to compromise the platform, potentially leading to a complete takeover and impacting confidentiality, integrity, and availability. This issue requires immediate attention to confirm if the affected

CVE advisoryCRITICAL

CVE-2026-60385

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows unauthenticated network attackers to take over the platform, impacting confidentiality, integrity, and availability. The Messaging Enabler component is affected, and successful exploitation could result in a complete compromise.

CVE advisoryCRITICAL

CVE-2026-60384

Oracle Fusion Middleware Service Delivery Platform Messaging Enabler Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform Messaging Enabler, allowing unauthenticated attackers with network access to achieve a complete takeover. This impacts confidentiality, integrity, and availability, making it a significant risk to the platform.

CVE advisoryCRITICAL

CVE-2026-60380

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform, exploitable via network access, could allow an unauthenticated attacker to achieve complete system takeover. This poses a significant risk to the availability and integrity of the platform.

CVE advisoryCRITICAL

CVE-2026-60379

Oracle Fusion Middleware Service Delivery Platform SOAP Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform, allowing unauthenticated network attackers to compromise the platform via SOAP. Successful exploitation could lead to a complete takeover of the platform and potentially impact additional products. This issue warrants attention due

CVE advisoryCRITICAL

CVE-2026-60378

Oracle Fusion Middleware Messaging Enabler Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform, enabling unauthenticated network attackers to achieve complete system takeover. This issue impacts confidentiality, integrity, and availability, and should be a concern if this platform is used.

CVE advisoryCRITICAL

CVE-2026-60377

Oracle Fusion Middleware Service Delivery Platform Messaging Enabler Vulnerability Affects Data and Availability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Service Delivery Platform, specifically within its Messaging Enabler component. This issue, exploitable by a low-privileged attacker with network access, could result in unauthorized data access, modification, or deletion, and potentially cause a partial den

CVE advisoryCRITICAL

CVE-2026-60376

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows unauthenticated attackers with network access to take over the platform, impacting confidentiality, integrity, and availability. This issue is easily exploitable and could lead to a complete compromise of the platform.

CVE advisoryCRITICAL

CVE-2026-60375

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform could allow an unauthenticated attacker with network access to take complete control of the platform. This could impact the confidentiality, integrity, and availability of services relying on the platform.

CVE advisoryCRITICAL

CVE-2026-60374

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker with network access to potentially take over the entire platform. This could impact the confidentiality, integrity, and availability of the platform.

CVE advisoryCRITICAL

CVE-2026-60365

Oracle WebLogic Server Proxy Plug-in Data Integrity and Confidentiality Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Weblogic Server's Proxy Plug-in, allowing unauthenticated attackers network access to compromise the plug-in. Successful exploitation could result in unauthorized access to or modification of critical data, potentially impacting additional products. This issue is significant be

CVE advisoryCRITICAL

CVE-2026-60364

Oracle Weblogic Server Proxy Plug-in Integrity Compromise

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Oracle Weblogic Server Proxy Plug-in could allow an unauthenticated attacker with network access to modify or delete critical data. This plug-in is often exposed at the network's edge, increasing the potential for compromise if reachable.

CVE advisoryCRITICAL

CVE-2026-60363

Oracle HTTP Server Apache Plugin Takeover Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle HTTP Server, allowing unauthenticated network attackers to take full control of the server, impacting confidentiality, integrity, and availability. This technology is relevant because it is often deployed publicly, making it reachable from the internet.

CVE advisoryCRITICAL

CVE-2026-60361

Oracle Unified Directory LDAP Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Unified Directory allows a low-privileged attacker with network access via LDAP to achieve a complete takeover of the directory service. This could impact additional products, posing significant risks to confidentiality, integrity, and availability.A critical vulnerability in Oracle U

CVE advisoryCRITICAL

CVE-2026-60355

Oracle Access Manager Authentication Engine Vulnerability Leads to Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated network attacker can compromise Oracle Access Manager, potentially leading to a complete takeover of the system. This easily exploitable vulnerability impacts the product's authentication engine, posing a critical risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60333

Oracle Access Manager Authentication Engine Vulnerability Allows Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with network access via HTTP to achieve a complete takeover of the system, potentially impacting other connected products. This issue poses a significant risk to identity and access management functions.

CVE advisoryCRITICAL

CVE-2026-60329

Oracle Identity Manager Remote Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Identity Manager allows unauthenticated network attackers to achieve a complete takeover. This could lead to significant impacts on data confidentiality, integrity, and availability. The affected technology is part of Oracle Fusion Middleware.

CVE advisoryCRITICAL

CVE-2026-60328

Oracle Access Manager Authentication Engine Vulnerability Allows Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access to compromise the system, potentially leading to a complete takeover. This impacts confidentiality, integrity, and availability, and the technology is often exposed externally.

CVE advisoryCRITICAL

CVE-2026-60326

Oracle Access Manager Authentication Engine Vulnerability Allows Data Compromise

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated network attackers to compromise the system, leading to unauthorized access or modification of critical data. This issue is relevant because Oracle Access Manager manages sensitive information and system access.

CVE advisoryCRITICAL

CVE-2026-60308

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated network access to achieve a complete system takeover. This impacts confidentiality, integrity, and availability, requiring confirmation of its use and potential exposure within your environment.

CVE advisoryCRITICAL

CVE-2026-60306

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Coherence, allowing unauthenticated attackers with network access to compromise the product and take control of the system. This could impact data confidentiality, integrity, and availability. Determine if your organization uses Oracle Coherence and if it is reachable.

CVE advisoryCRITICAL

CVE-2026-60302

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware, that allows an unauthenticated attacker with network access to potentially take over the system. This issue impacts confidentiality, integrity, and availability, with a CVSS score of 9.8.

CVE advisoryCRITICAL

CVE-2026-60300

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Coherence could allow unauthenticated attackers with network access to take over the system, impacting data confidentiality, integrity, and availability. It is uncertain if this technology is used or exposed within the environment, warranting investigation into its presence and access

CVE advisoryCRITICAL

CVE-2026-60299

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. Readers should care if Oracle Coherence is in use, as an attacker could gain control of this data management

CVE advisoryCRITICAL

CVE-2026-60296

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to achieve a full system takeover, impacting confidentiality, integrity, and availability. This issue, exploitable via TCP, could lead to significant disruption. Determining the relevance and exposure of your Oracle Coherence instance

CVE advisoryCRITICAL

CVE-2026-60294

Oracle WebLogic Server SOAP Vulnerability Allows Unauthenticated Server Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via SOAP to compromise the server, potentially leading to a complete takeover. This impacts confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60292

Oracle WebLogic Server Core Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access to completely compromise the server, impacting confidentiality, integrity, and availability. This threat is external and very likely to be exploited via HTTP.

CVE advisoryCRITICAL

CVE-2026-60289

Oracle Coherence Core Remote Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to compromise the system, potentially leading to a full takeover. This issue impacts core functionality, and successful exploitation could result in significant data and operational disruptions. It is important to determine if Oracle

CVE advisoryCRITICAL

CVE-2026-60288

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to achieve a complete takeover of the system. This issue impacts confidentiality, integrity, and availability, and requires attention due to its ease of exploitation and potential for system compromise.

CVE advisoryCRITICAL

CVE-2026-60287

Oracle Coherence Network Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. The primary concern is determining if your Oracle Coherence deployment is reachable, as it's typi

CVE advisoryCRITICAL

CVE-2026-60286

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence that allows unauthenticated network attackers via HTTP to take over the system, potentially impacting data confidentiality, integrity, and availability. This issue is reachable remotely and could lead to a complete compromise of the Coherence service.

CVE advisoryCRITICAL

CVE-2026-60280

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated network attackers to achieve a complete system takeover. This impacts confidentiality, integrity, and availability, necessitating confirmation of its use and potential exposure.

CVE advisoryCRITICAL

CVE-2026-60279

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, an Oracle Fusion Middleware component, allows unauthenticated network attackers to take over affected systems, impacting data confidentiality, integrity, and availability. It is uncertain if this technology is deployed within the organization, necessitating confirmation to

CVE advisoryCRITICAL

CVE-2026-60278

Oracle Coherence Core Takeover Vulnerability CVE-2026-60278

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, an Oracle Fusion Middleware component, allowing unauthenticated network attackers to compromise the system via HTTP. Successful exploitation could lead to a complete takeover, impacting data confidentiality, integrity, and availability. It is important to determine i

CVE advisoryCRITICAL

CVE-2026-60276

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to take over the system via HTTPS, potentially impacting data confidentiality, integrity, and availability. The main concern is confirming if affected Oracle Coherence instances are reachable and relevant to the business.

CVE advisoryCRITICAL

CVE-2026-60275

Oracle Coherence Unauthenticated Network Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, allowing unauthenticated attackers with network access to achieve a complete takeover of the system. This could impact confidentiality, integrity, and availability. It is important to determine if your environment uses this technology and if it is exposed to potentia

CVE advisoryCRITICAL

CVE-2026-60274

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence that allows unauthenticated network attackers to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. Confirming if Oracle Coherence is in use is the primary concern.

CVE advisoryCRITICAL

CVE-2026-60272

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware. An unauthenticated attacker with network access could exploit this by sending a crafted HTTP request, potentially leading to a complete takeover of the Coherence system. This impacts confidentiality, integrity, and availabilit

CVE advisoryCRITICAL

CVE-2026-60269

Oracle Coherence Core Vulnerability Allows Unauthenticated Network Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence that allows an unauthenticated network attacker to achieve a complete system takeover. This issue impacts confidentiality, integrity, and availability. The affected technology is a component of Oracle Fusion Middleware. Given the potential for unauthorized control, un

CVE advisoryCRITICAL

CVE-2026-60267

Oracle Coherence Core Unauthorized Data Manipulation and Access Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated attackers with network access to compromise data. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, or complete access to all accessible data. This impacts data c

CVE advisoryCRITICAL

CVE-2026-60264

Oracle Coherence Core HTTP/2 Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, allowing unauthenticated network attackers to compromise the system. This could result in a complete takeover of Oracle Coherence, affecting its confidentiality, integrity, and availability. Confirming relevance and exposure within your environment is crucial.

CVE advisoryCRITICAL

CVE-2026-60259

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware. Unauthenticated attackers with network access can exploit this by sending HTTP requests, potentially leading to a complete takeover of the system. This could impact confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60258

Oracle Coherence Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, an Oracle Fusion Middleware component, allows unauthenticated network attackers to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability, warranting attention to confirm if this typically internal technology

CVE advisoryCRITICAL

CVE-2026-60257

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware, that can be exploited by unauthenticated attackers with network access to achieve a complete takeover of the system. This impacts confidentiality, integrity, and availability, necessitating an assessment of affected instances

CVE advisoryCRITICAL

CVE-2026-60256

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to completely compromise the system. Successful exploitation could lead to a full takeover, impacting confidentiality, integrity, and availability. The primary concern is to confirm its relevance and exposure within our en

CVE advisoryCRITICAL

CVE-2026-60253

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, allowing unauthenticated attackers network access to compromise the system. Successful exploitation could lead to a complete takeover, impacting confidentiality, integrity, and availability. While typically deployed internally, its reachability requires confirmation

CVE advisoryCRITICAL

CVE-2026-60251

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to take over the system, impacting confidentiality, integrity, and availability. You should care because this could lead to a complete compromise of your Oracle Coherence environments.

CVE advisoryCRITICAL

CVE-2026-60247

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware, allowing unauthenticated attackers network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover, impacting confidentiality, integrity, and availability. Readers should care becaus

CVE advisoryCRITICAL

CVE-2026-60246

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a middleware component, allowing unauthenticated network attackers to compromise and take over the system. This could impact data confidentiality, integrity, and availability. Confirmation of its relevance and exposure is necessary due to its network-accessible natur

CVE advisoryCRITICAL

CVE-2026-60244

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to compromise the system, potentially leading to a complete takeover. This impacts confidentiality, integrity, and availability, making it crucial to assess the exposure and criticality of Oracle Coherence deployments.

CVE advisoryCRITICAL

CVE-2026-60242

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, part of Oracle Fusion Middleware, that allows unauthenticated network attackers to compromise the system via HTTP, potentially leading to a complete takeover. This could impact data confidentiality, integrity, and availability, making it important to assess its reach

CVE advisoryCRITICAL

CVE-2026-60241

Oracle Coherence Core Remote Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to a complete takeover. This issue impacts confidentiality, integrity, and availability, making it important to confirm its relevance and exposure within the environme

CVE advisoryCRITICAL

CVE-2026-60240

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to gain complete control of the system, impacting confidentiality, integrity, and availability. Confirming the use of Oracle Coherence in the environment is the primary concern due to the potential for full system takeover.

CVE advisoryCRITICAL

CVE-2026-60239

Oracle Coherence Unauthorized Data Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows low-privileged attackers with network access to compromise the product. This could lead to unauthorized access, modification, or deletion of critical data, potentially impacting other connected products. The issue is reachable via HT

CVE advisoryCRITICAL

CVE-2026-60236

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to gain complete control of the system, impacting confidentiality, integrity, and availability. The ease of exploitation and severe potential consequences warrant attention if Oracle Coherence is deployed within the environment.

CVE advisoryCRITICAL

CVE-2026-60234

Oracle Coherence Network Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, an Oracle Fusion Middleware component, allowing unauthenticated network attackers to potentially achieve full system takeover. This issue impacts confidentiality, integrity, and availability, necessitating an understanding of its presence and reachability within your

CVE advisoryCRITICAL

CVE-2026-60230

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated network attackers to achieve a complete takeover. This could impact confidentiality, integrity, and availability, necessitating confirmation of its presence and exposure within the environment.

CVE advisoryCRITICAL

CVE-2026-60229

Oracle Coherence TCP Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated attackers with network access to achieve a complete system takeover. This impacts data confidentiality, integrity, and availability, necessitating confirmation of its use and exposure within our environment.

CVE advisoryCRITICAL

CVE-2026-60228

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to fully compromise the system. This could impact data confidentiality, integrity, and availability, leading to a complete takeover of the Oracle Coherence environment. The primary concern is to verify if your deployment i

CVE advisoryCRITICAL

CVE-2026-60227

Oracle Coherence Core Vulnerability Allows Network Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to compromise the system, leading to a full takeover. This affects confidentiality, integrity, and availability, warranting attention to its relevance and exposure within the environment.

CVE advisoryCRITICAL

CVE-2026-60226

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, allows unauthenticated network attackers to gain complete control. This could impact the confidentiality, integrity, and availability of data. While typically deployed in backend systems, its network exploitability warrants an assess

CVE advisoryCRITICAL

CVE-2026-60224

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, allowing unauthenticated network attackers to compromise the system and potentially take it over. This impacts confidentiality, integrity, and availability, with a high CVSS score. Confirmation of its reachability and relevance is important, as Coherence typically su

CVE advisoryCRITICAL

CVE-2026-60221

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to compromise the system via TCP, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. It is important to confirm the relevance and network exposure of your Oracle Coherence deployments.

CVE advisoryCRITICAL

CVE-2026-60220

Oracle Coherence Network Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A network vulnerability in Oracle Coherence allows unauthenticated attackers to compromise data, potentially leading to unauthorized access, creation, deletion, or modification of critical information. This issue is reachable via the network and requires user interaction for successful exploitation. The vulnerability's

CVE advisoryCRITICAL

CVE-2026-60219

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated attackers with network access to take over the system, impacting data confidentiality, integrity, and availability. Readers should care because successful exploitation can lead to a complete compromise of Oracle Coherence, a component often used in ent

CVE advisoryCRITICAL

CVE-2026-60216

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence allows unauthenticated network attackers to take over the system, impacting confidentiality, integrity, and availability. Reachability and usage within your environment are key concerns, as successful exploitation could lead to a complete compromise of the Oracle Coherence c

CVE advisoryCRITICAL

CVE-2026-60215

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated network attackers to achieve a full system takeover. This impacts confidentiality, integrity, and availability, posing a significant risk to data and clustered applications.

CVE advisoryCRITICAL

CVE-2026-60210

Oracle Coherence Core Vulnerability Allows Unauthenticated Network Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware. An unauthenticated attacker with network access could potentially take over the product, impacting confidentiality, integrity, and availability. The reachability of affected systems via TCP needs to be determined to understand

CVE advisoryCRITICAL

CVE-2026-60209

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, allows unauthenticated network attackers to achieve a complete system takeover. This impacts confidentiality, integrity, and availability. The concern is whether your specific deployment is relevant and potentially exposed to this th

CVE advisoryCRITICAL

CVE-2026-60208

Oracle WebLogic Server Core Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access to gain unauthorized control over sensitive data, potentially leading to its creation, deletion, or modification. Because Oracle WebLogic Server is commonly deployed in internet-facing configurations, this vulnerabil

CVE advisoryCRITICAL

CVE-2026-60206

Oracle WebLogic Server SAML Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebLogic Server, enabling a low-privileged attacker with network access to achieve server takeover. This flaw, affecting the SAML component, could have significant downstream effects on connected products and impact data confidentiality, integrity, and availability. It is impor

CVE advisoryCRITICAL

CVE-2026-60205

Oracle WebLogic Server Core Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated network attackers to compromise the server, potentially leading to a complete takeover. This issue affects the core component and can impact confidentiality, integrity, and availability. Because it is exploitable over TCP without authentication,

CVE advisoryCRITICAL

CVE-2026-60204

Oracle WebLogic Server T3 IIOP Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server could allow an unauthenticated attacker with network access to take over the server, impacting its confidentiality, integrity, and availability. Given that WebLogic is often internet-facing, confirming its presence and network exposure in your environment is crucial to

CVE advisoryCRITICAL

CVE-2026-60202

Oracle WebLogic Server Unauthenticated Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability affects Oracle WebLogic Server, allowing unauthenticated attackers with network access to potentially take complete control of the server. This could impact confidentiality, integrity, and availability. It is important to identify if this technology is in use and exposed to understand the poten

CVE advisoryCRITICAL

CVE-2026-60200

Oracle WebLogic Server SOAP Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server, a widely used enterprise application server, allows unauthenticated attackers with network access via SOAP to potentially take over the system. This issue impacts confidentiality, integrity, and availability, making it crucial to identify affected instances and assess

CVE advisoryCRITICAL

CVE-2026-60199

Oracle WebLogic Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated network attackers to compromise and take over the server via HTTP. This issue impacts the Core component and could lead to significant confidentiality, integrity, and availability impacts. Organizations should verify if they use Oracle WebLogic S

CVE advisoryCRITICAL

CVE-2026-60198

Oracle WebLogic Server Core Vulnerability Allows Server Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebLogic Server's Core component that could allow an unauthenticated attacker with network access via T3 or IIOP to take over the server. This issue impacts confidentiality, integrity, and availability, and given the product's common use as an internet-facing application server

CVE advisoryCRITICAL

CVE-2026-60197

Oracle Coherence Core Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Coherence, an Oracle Fusion Middleware component, could allow an unauthenticated attacker with network access to achieve a complete takeover of the system. This poses a risk to confidentiality, integrity, and availability if the affected technology is reachable. Readers should care to

CVE advisoryCRITICAL

CVE-2026-60173

Oracle BI Publisher Unauthenticated Network Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle BI Publisher, part of Oracle Analytics, allows unauthenticated attackers with network access to completely take over the system. This impacts the confidentiality, integrity, and availability of reporting and analytics capabilities. Uncertainty exists regarding specific product version

CVE advisoryCRITICAL

CVE-2026-60168

Oracle Hospitality Simphony Network Data Integrity and Denial of Service Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hospitality Simphony allows unauthenticated network attackers to alter or delete critical data or cause system crashes. Confirmation is needed to determine if this product is used and exposed within our environment, posing a risk to data integrity and availability.

CVE advisoryCRITICAL

CVE-2026-47731

AMMOS Instrument Toolkit BSC Path Traversal Leading to File Append

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the AMMOS Instrument Toolkit's Binary Stream Capture component that allows remote, unauthenticated attackers to write to arbitrary files on the system. This path traversal vulnerability could impact system integrity, and its relevance depends on whether the toolkit is deployed and exposed with

CVE advisoryCRITICAL

CVE-2026-47056

Oracle Data Integrator Rest Service Vulnerability Enables Full Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Data Integrator's Rest Service component allows unauthenticated network attackers to achieve a full takeover. Although the vulnerability resides in Oracle Data Integrator, its scope may extend to affect other products, posing a significant risk to data management operations.

CVE advisoryCRITICAL

CVE-2026-47040

Oracle Net Services Remote Access and Denial of Service Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Net Services can allow an unauthenticated attacker with network access to compromise the service, potentially leading to unauthorized access to critical data or a denial of service. This issue affects specific supported versions of Oracle Database Server.

CVE advisoryCRITICAL

CVE-2026-46994

Oracle Enterprise Manager Agent Next Gen Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Enterprise Manager Base Platform's Agent Next Gen component allows unauthenticated attackers with network access to potentially take over the system. This easily exploitable issue poses a significant risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-46989

Oracle Enterprise Manager UI Framework Vulnerability Allows Unauthorized Access and Data Manipulation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Enterprise Manager Base Platform's UI Framework could allow a low-privileged attacker with network access to compromise the system, potentially leading to unauthorized access to critical data, data modification, or a partial denial of service. This issue may impact products beyond the Base Pla

CVE advisoryCRITICAL

CVE-2026-46983

Oracle Retail Integration Bus Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Retail Integration Bus could allow an unauthenticated attacker with network access to take over the system, impacting confidentiality, integrity, and availability. This requires attention due to the potential for complete system compromise.

CVE advisoryCRITICAL

CVE-2026-46982

Oracle Retail Integration Bus Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker with network access via HTTP can compromise the Oracle Retail Integration Bus. Successful exploitation may result in a complete takeover of the system, impacting confidentiality, integrity, and availability. This vulnerability is in the Oracle Retail Integration Bus product of Oracle Retail

CVE advisoryCRITICAL

CVE-2026-46876

Oracle Application Testing Suite Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Application Testing Suite that allows an unauthenticated attacker with network access to achieve a complete takeover. This could impact the confidentiality, integrity, and availability of the testing suite and its managed data, potentially disrupting quality assurance operation

CVE advisoryCRITICAL

CVE-2026-8983

Autel Maxi Charger Authentication Bypass via Hard-coded Token

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Autel Maxi Charger firmware contains a hard-coded token that bypasses authorization for management functions, allowing unauthenticated attackers network access to privileged operations. This technology is used for electric vehicle charging infrastructure, and its exposure could lead to unauthorized control or configura

CVE advisoryCRITICAL

CVE-2026-8982

Autel Maxi Charger Undocumented Privileged Accounts Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware, which could allow an attacker to authenticate to the web management interface with administrative privileges. This is possible if the attacker knows the specific algorithm and device-specific inputs used to derive the passwords for these

CVE advisoryCRITICAL

CVE-2026-65057

Keep Server-Side Request Forgery via Healthcheck Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in an unauthenticated healthcheck endpoint allows attackers to make arbitrary backend HTTP requests, potentially stealing cloud credentials and performing internal network reconnaissance. The primary concern is confirming if this technology is in use and assessing its exposur

CVE advisoryHIGH

CVE-2026-63764

lmdeploy API Server Side Request Forgery via HTTP Redirect

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability exists in lmdeploy's API server, allowing unauthenticated attackers to access internal services and cloud metadata by using a crafted image URL that redirects to internal targets. This bypasses safety checks, potentially exposing sensitive information. Understanding your expo

CVE advisoryCRITICAL

CVE-2026-52472

Wgcloud 3.6.4 SQL Injection Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in Wgcloud, a technology used for monitoring and management. This flaw could permit remote attackers to escalate privileges by injecting malicious SQL code via the PortInfoMapper.xml file. If reachable, this could lead to unauthorized access and control over the system, imp

CVE advisoryCRITICAL

CVE-2026-52470

Crocus SQL Injection Privilege Escalation via RecordStateMapper.xml

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability exists in Crocus, potentially allowing remote attackers to escalate privileges via the RecordStateMapper.xml file. This could lead to unauthorized access and modification of system data. It is uncertain if this technology is deployed in a manner that makes it reachable or relevant

CVE advisoryCRITICAL

CVE-2026-47708

MCP-for-Stata Parameter Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

MCP-for-Stata, a component for integrating Stata into agents, contains a vulnerability allowing an attacker to inject arbitrary Stata commands by manipulating a log file parameter. This could lead to unauthorized command execution. Confirm if this technology is in use and if it is reachable.

CVE advisoryCRITICAL

CVE-2026-30631

bytebot-ai Arbitrary Code Execution via Crafted Path

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in bytebot-ai allows unauthenticated attackers to execute arbitrary code via a crafted path to `computer_write_file`. This could enable unauthorized code execution on affected systems, making it crucial to confirm the presence and exposure of this AI software component.

CVE advisoryCRITICAL

CVE-2026-64879

Audit File Upload Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in file upload functionality that allows for command injection due to a lack of filename sanitization. An attacker could exploit this by uploading a malicious file, potentially leading to arbitrary command execution on the system. This risk is relevant if the audit file upload feature is reachabl

CVE advisoryCRITICAL

CVE-2026-64878

Analysis REST Endpoint RCE via Input Validation Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unvalidated input vulnerability in asset filter parameters allows shell metacharacters to bypass command argument handling, leading to remote code execution as a low-privileged OS user via the Analysis REST endpoint. This issue is significant because it can be reached via a network and offers an attacker the ability

CVE advisoryCRITICAL

CVE-2026-59147

Data::DisjointSet::Shared Out-of-Bounds Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Data::DisjointSet::Shared Perl library, allowing for out-of-bounds memory reads and writes via an unvalidated index. This could lead to memory corruption or process crashes if an attacker can write to a specially crafted backing file. Organizations should determine if this library

CVE advisoryCRITICAL

CVE-2026-59145

Data::Intern::Shared Out-of-Bounds Read via Unvalidated Indices

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Perl module has an out-of-bounds read vulnerability due to unvalidated indices in its data structures. Local attackers with write access to the module's backing file could exploit this to read adjacent process memory. Review is needed to determine relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-59144

Perl Data::RingBuffer::Shared Stack Buffer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A stack buffer overflow exists in Perl's Data::RingBuffer::Shared, allowing a local attacker with write access to the backing file to cause memory corruption. This could lead to system compromise. The relevance depends on whether this module is used and if its backing files are accessible for manipulation.

CVE advisoryCRITICAL

CVE-2026-50755

DayuanJiang next-ai-draw-io Information Disclosure via X-Forwarded-For Header

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in DayuanJiang next-ai-draw-io could allow remote attackers to obtain sensitive information by manipulating the X-Forwarded-For header. This could lead to unauthorized access to data, making it important to verify if this application is present and reachable within the environment.

CVE advisoryCRITICAL

CVE-2026-59142

Data::HashMap::Shared Out-of-Bounds Read via Unvalidated Offset

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Data::HashMap::Shared for Perl, allowing an out-of-bounds read via an unvalidated offset and length in `shm_str_copy`. A local attacker with write access to the backing file could trigger this by poisoning record data, potentially leading to adjacent memory disclosure or process crashes. Confi

CVE advisoryCRITICAL

CVE-2026-59141

Data::RadixTree::Shared Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Data::RadixTree::Shared Perl library could allow an out-of-bounds read. This occurs when unvalidated indices in the `rdx_find_locked` function are used, potentially leading to the disclosure of adjacent memory or a process crash if a local attacker can modify the backing file. It is uncertain if

CVE advisoryCRITICAL

CVE-2026-59140

Data::SortedSet::Shared Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in a Perl library that handles shared data, allowing an attacker with local write access to a backing file to trigger an out-of-bounds read. This could lead to the disclosure of adjacent memory or a process crash, impacting data confidentiality and system stability. The reader should care because

CVE advisoryCRITICAL

CVE-2026-59139

Data::ReqRep::Shared Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Data::ReqRep::Shared Perl module that allows an out-of-bounds read. An attacker with write access to a backing file could manipulate memory offsets and lengths to read adjacent memory or cause a crash. The primary concern is determining if this technology is used within the environment.

CVE advisoryCRITICAL

CVE-2016-20096

Linknat VOS SQL Injection via Login

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Linknat VOS3000 and VOS2009 software, allowing remote attackers to execute arbitrary SQL commands via the login endpoint. This could lead to the extraction of sensitive data, including plaintext credentials. The vulnerability is concerning due to its presence in

CVE advisoryCRITICAL

CVE-2026-47416

PraisonAI Platform Workspace Member Role Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The PraisonAI Platform contains a vertical privilege escalation vulnerability in its role management endpoint. A user with member access can exploit this flaw to gain administrator or owner privileges, potentially allowing unauthorized control over workspace members and roles. The exact business impact is uncertain as

CVE advisoryCRITICAL

CVE-2026-47413

PraisonAI Platform Privilege Escalation via Workspace Member Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability in the PraisonAI Platform allows a user with member access to inject other users, including themselves, as workspace owners. This could lead to unauthorized control and disruption of multi-agent teams. The platform is reachable via its network, increasing potential exposure.

CVE advisoryCRITICAL

CVE-2026-47410

PraisonAI Platform Insecure Default JWT Secret Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The PraisonAI Platform has a vulnerability where an insecure default cryptographic key allows attackers to forge authentication tokens and gain unauthorized access to any user account, including administrators. This issue impacts systems prior to version 0.1.4 that have not explicitly reconfigured the default settings.

CVE advisoryCRITICAL

CVE-2026-47407

PraisonAI Platform Cross-Tenant Access and Privilege Escalation Vulnerabilities

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

PraisonAI Platform vulnerabilities allow unauthorized users to access and manipulate data across workspaces and escalate privileges. An attacker can bypass authentication to read, update, or delete resources from other tenants by manipulating workspace IDs in API requests. Additionally, flaws in member management route

CVE advisoryCRITICAL

CVE-2026-64825

Home Assistant Core Unauthenticated Arbitrary File Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Home Assistant Core allows unauthenticated attackers to write arbitrary files to the host filesystem during initial setup. Successful exploitation could lead to full system compromise if the process runs as root.

CVE advisoryCRITICAL

CVE-2026-64824

Home Assistant Core Backup Restore Path Traversal Leads to Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in Home Assistant Core's backup-restore function allows authenticated attackers to write files to arbitrary filesystem locations by supplying a crafted tar archive. This could lead to remote code execution if the Home Assistant process runs with root privileges, potentially compromising t

CVE advisoryCRITICAL

CVE-2026-47396

PraisonAI Call Server Unauthenticated Agent Control API Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in PraisonAI's call server, allowing unauthenticated remote access to its agent control API when a token is not configured. This could permit unauthorized users to list, inspect, invoke, or unregister agents, posing a significant security risk if the call server is network-exposed.

CVE advisoryCRITICAL

CVE-2026-47393

PraisonAI API Generation Defaulting to No Authentication

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The PraisonAI multi-agent system's API server code generator can create servers that lack authentication by default, potentially exposing sensitive operations. This vulnerability could allow unauthenticated network access, leading to unauthorized execution of AI orchestration tasks and risk to API keys.

CVE advisoryCRITICAL

CVE-2026-47392

PraisonAI `execute_code()` Sandbox Bypass Allows OS Command Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in PraisonAI's code execution function allows bypassing its sandbox, leading to arbitrary OS command execution. This novel bypass circumvents previous security patches. This issue is relevant if the PraisonAI system is reachable, as it could compromise host systems.

CVE advisoryCRITICAL

CVE-2026-47391

PraisonAI Unauthenticated Python Eval RCE in A2A Server Example.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can execute arbitrary Python code on PraisonAI systems by exploiting an unauthenticated A2A server endpoint that uses `eval()`. This vulnerability affects deployments using the official A2A example or similar unauthenticated public A2A setups, potentially compromising confidentiality

CVE advisoryCRITICAL

CVE-2026-28321

SolarWinds Serv-U Broken Access Control Allows Arbitrary File Read Write and Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical broken access control vulnerability in SolarWinds Serv-U could allow an administrator to read or write arbitrary files, potentially leading to privilege escalation and code execution. While this requires administrator access and has a reduced impact on Windows, Serv-U's typical role as a network-facing gatew

CVE advisoryCRITICAL

CVE-2026-28317

SolarWinds Serv-U Privilege Escalation via Insecure Direct Object Reference

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical flaw in SolarWinds Serv-U allows privilege escalation for attackers with domain administrator access. This vulnerability, an insecure direct object reference, could enable unauthorized actions within the application. While the impact is reduced in Windows deployments, the risk of privilege escalation is a co

CVE advisoryCRITICAL

CVE-2026-28316

SolarWinds Serv-U Privilege Escalation via Insecure Direct Object Reference.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in SolarWinds Serv-U allowing an administrator to escalate privileges to execute commands as the root user. This insecure direct object reference could grant unauthorized system control, with potentially greater impact in non-Windows environments.

CVE advisoryCRITICAL

CVE-2026-28314

SolarWinds Serv-U Insecure Direct Object Reference Leads to Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SolarWinds Serv-U software could allow an authenticated attacker to take over user accounts, potentially leading to unauthorized access and data exposure. The impact is lower in Windows deployments, but affected systems should be reviewed for relevance.

CVE advisoryCRITICAL

CVE-2026-28313

SolarWinds Serv-U SMTP Hijacking via Insecure Direct Object Reference

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SolarWinds Serv-U has an insecure direct object reference vulnerability that can lead to SMTP hijacking and account takeover. The risk is reduced on Windows deployments. Confirmation of usage and assessment of potential exposure are recommended.

CVE advisoryCRITICAL

CVE-2026-28312

SolarWinds Serv-U Privilege Escalation to System Administrator and Root Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability in SolarWinds Serv-U could allow a privileged attacker to gain system administrator access and execute code as root. The impact is noted as lower on Windows deployments. This issue is relevant if Serv-U is in use and reachable by an authenticated user.

CVE advisoryCRITICAL

CVE-2026-28310

SolarWinds Serv-U Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability in SolarWinds Serv-U allows a domain administrator to gain system administrator privileges. This could impact system integrity and data access, with potentially reduced impact in Windows deployments. Confirming usage and exposure is key to assessing risk.

CVE advisoryCRITICAL

CVE-2026-28309

SolarWinds Serv-U Broken Access Control Allows Domain Admin to Create System Admins.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical broken access control vulnerability exists in SolarWinds Serv-U, allowing a domain administrator to create system administrator accounts. This could lead to unauthorized system control if the technology is deployed and reachable.

CVE advisoryCRITICAL

CVE-2026-28307

SolarWinds Serv-U Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability in SolarWinds Serv-U allows a domain user to gain administrator privileges, which could lead to system compromise. The impact is noted as lower in Windows deployments. This issue is reachable via the network and warrants attention to confirm its relevance and assess potential exposu

CVE advisoryCRITICAL

CVE-2026-28306

SolarWinds Serv-U Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability exists in SolarWinds Serv-U, potentially allowing a domain administrator to attain system administrator privileges. This could impact system confidentiality, integrity, and availability. The technology is a file transfer solution often exposed externally.

CVE advisoryCRITICAL

CVE-2026-28305

SolarWinds Serv-U Insecure Direct Object Reference Leads to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SolarWinds Serv-U has a critical vulnerability allowing remote code execution. An attacker with administrative privileges could exploit this to run arbitrary code with root access, though impact is reduced on Windows. This requires confirming if Serv-U is deployed and accessible in your environment.

CVE advisoryCRITICAL

CVE-2026-65048

Ninja Forms Unauthenticated Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated stored cross-site scripting vulnerability in the Ninja Forms plugin for WordPress allows attackers to inject malicious scripts via form submissions. These scripts can execute in an administrator's browser when viewing submissions, potentially leading to session theft or unauthorized site modification

CVE advisoryCRITICAL

CVE-2025-66390

Azure API Management Cross-Tenant Signup Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Azure API Management has a potential configuration issue where self-service signup can be bypassed for different tenants. This could allow an attacker to reuse a signup flow to access another tenant, even if signup is disabled in the user interface. The vendor states this is a configuration/state issue, not a

CVE advisoryCRITICAL

CVE-2026-16408

Firefox Audio/Video Playback Integer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Firefox's audio/video playback component has been identified, posing a critical risk. This vulnerability could allow an attacker to execute arbitrary code if a user visits a malicious webpage, potentially impacting confidentiality, integrity, and availability. It is important to confirm if this c

CVE advisoryCRITICAL

CVE-2026-16407

Firefox Service Workers Mitigation Bypass Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical mitigation bypass vulnerability exists in the Service Workers component of Firefox. If reachable, this could allow attackers to bypass security restrictions, potentially impacting the integrity of client-side operations. This issue is relevant for maintaining a secure digital environment.

CVE advisoryCRITICAL

CVE-2026-16406

Firefox Networking Mitigation Bypass Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in a browser's networking component that allows security mitigations to be bypassed. If reachable, this could lead to unauthorized access to or alteration of sensitive information. This issue is relevant due to the potential impact on data confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-16402

Firefox Graphics ImageLib Integer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Firefox's Graphics: ImageLib component allows for high-impact compromise of a user's browser if they load a crafted image. This vulnerability could affect confidentiality, integrity, and availability. Its relevance depends on whether the affected browser version is present in the environment.

CVE advisoryHIGH

CVE-2026-16396

Firefox WebExtensions Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in WebExtensions, which could allow an attacker to escalate privileges. While the specific impact and exploitation methods are under analysis, this issue relates to components within a web browser. Readers should care to confirm if their environment uses affected browser extensions and a

CVE advisoryCRITICAL

CVE-2026-16395

Firefox AudioVideo Integer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in the Audio/Video component of Firefox could allow for significant compromise of confidentiality, integrity, and availability if reachable. This vulnerability may be triggered by processing malicious media content, potentially impacting user data and allowing for system compromise.

CVE advisoryCRITICAL

CVE-2026-16394

Firefox DOM Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the web browser's DOM security component that could allow mitigation bypass. While a user must interact with malicious content, this flaw may enable unauthorized access or manipulation of web content. Its relevance and exposure within our environment require confirmation.

CVE advisoryCRITICAL

CVE-2026-16393

Firefox Graphics WebGPU Component Incorrect Boundary Conditions Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's Graphics: WebGPU component due to incorrect boundary conditions. This flaw could lead to impacts on confidentiality and availability if a user interacts with malicious content. While user interaction is required, its critical nature warrants review of system relevance and ex

CVE advisoryCRITICAL

CVE-2026-16392

JIT Miscompilation in Mozilla JavaScript Engine Allows Arbitrary Write and Denial of Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the JavaScript engine's JIT component could permit an attacker to impact application integrity or cause a denial of service. This is because a miscompilation within the JIT process can be triggered. This issue affects client-side applications, such as browsers and email clients.

CVE advisoryCRITICAL

CVE-2026-16390

Firefox Enterprise Policies Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A mitigation bypass vulnerability exists in the Enterprise Policies component of Mozilla products. If reachable, an attacker could bypass security measures related to enterprise policies, potentially leading to unauthorized actions. This issue affects the enforcement of organizational policies.

CVE advisoryCRITICAL

CVE-2026-16389

NSS Integer Overflow Vulnerability in Firefox

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Firefox's NSS library allows for an integer overflow due to incorrect boundary conditions. This could lead to system compromise if exploited. The reader should care because it may affect sensitive data and system integrity, with potential for remote code execution.

CVE advisoryCRITICAL

CVE-2026-16388

Firefox DOM Networking Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in Firefox's DOM: Networking component. If reached, this flaw could allow unauthorized actions or access to system and user data. Confirming relevance to your environment is crucial due to the potential for bypass of security restrictions.

CVE advisoryCRITICAL

CVE-2026-16387

Firefox Site Isolation Vulnerability Allows Widespread Impact.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A site isolation vulnerability in Firefox's networking component could allow unauthorized access to sensitive information or control of a user's browsing session. While exploitation requires user interaction with a malicious website, the potential impact on confidentiality, integrity, and availability is high. Confirmi

CVE advisoryCRITICAL

CVE-2026-16383

Firefox DOM Networking Mitigation Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A mitigation bypass vulnerability in the browser's DOM and networking component could allow an attacker to bypass security measures. If reachable, this could affect sensitive information or lead to unintended actions within the browser environment when interacting with specially crafted web pages. This issue has been a

CVE advisoryCRITICAL

CVE-2026-16381

Firefox Networking DNS Same-Origin Policy Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical same-origin policy bypass vulnerability exists in the Networking: DNS component of Firefox browsers, potentially allowing malicious content to circumvent security restrictions and access or modify sensitive information. While the exact business impact and relevance depend on whether affected browser versions

CVE advisoryCRITICAL

CVE-2026-16380

Firefox Networking Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A mitigation bypass vulnerability exists in Firefox's Networking component, potentially impacting data confidentiality and integrity if reachable. This issue does not appear to have significant internet-facing attack surface for common deployments. Uncertainty remains regarding specific affected data and business impac

CVE advisoryHIGH

CVE-2026-16379

Firefox DOM Content Process Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A privilege escalation vulnerability exists in the DOM: Content Processes component of a web browser, potentially allowing an attacker to gain elevated privileges on a user's system if reachable. This is a critical issue that could impact the integrity and availability of a user's browsing session. The exact business i

CVE advisoryCRITICAL

CVE-2026-16377

Firefox PDF Viewer Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical mitigation bypass vulnerability exists in the PDF Viewer component, potentially allowing attackers to bypass security measures by tricking users into opening malicious PDF files. This could lead to significant impacts on system and user data, necessitating an assessment of affected browser versions and user

CVE advisoryHIGH

CVE-2026-16372

Firefox DOM Content Process Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical privilege escalation vulnerability exists in Firefox's DOM Content Processes component. This could allow an attacker to gain elevated privileges on a user's system if they are tricked into visiting a malicious webpage. The integrity and confidentiality of the system could be impacted.

CVE advisoryHIGH

CVE-2026-16371

Firefox DOM Navigation Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical privilege escalation vulnerability exists in the DOM: Navigation component of the Firefox browser, potentially allowing unauthorized actions with elevated permissions. While the exact impact and reachability require further analysis, this flaw underscores the importance of securing browser components.

CVE advisoryCRITICAL

CVE-2026-16370

Firefox DOM Networking Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A mitigation bypass vulnerability exists in the DOM: Networking component of the Firefox web browser. If reachable, this could allow for bypassing security mitigations, potentially affecting data confidentiality and integrity. While user interaction with a malicious site is likely required for exploitation, the critica

CVE advisoryCRITICAL

CVE-2026-16369

Firefox WebAssembly Integer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Firefox's WebAssembly component could allow an attacker to compromise confidentiality, integrity, and availability if a user visits a malicious website. The vulnerability exists in the processing of specially crafted WebAssembly modules. While fixed in newer Firefox versions, its relevance to the

CVE advisoryCRITICAL

CVE-2026-16368

Firefox JavaScript WebAssembly Boundary Condition Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's JavaScript and WebAssembly component due to incorrect boundary conditions. This flaw could potentially lead to unauthorized access, modification of data, or disruption of services if exploited via a malicious webpage.

CVE advisoryCRITICAL

CVE-2026-16367

Firefox Disability Access API Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in a web browser's Disability Access APIs component, enabling sandbox escape. If reached, an attacker could potentially compromise a user's system. This threat, while unlikely to be externally exposed, warrants attention for maintaining security.

CVE advisoryHIGH

CVE-2026-16366

Firefox DOM Navigation Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical privilege escalation vulnerability exists in the DOM: Navigation component of a web browser, which could allow an attacker to gain elevated access if a user visits malicious content. This flaw impacts the confidentiality, integrity, and availability of the affected system. The vulnerability is classified as

CVE advisoryCRITICAL

CVE-2026-16364

Audio/Video Playback Vulnerability in Firefox

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An incorrect boundary condition in the Audio/Video playback component of a web browser could allow an attacker to access or modify data. This vulnerability is present when the component processes network-supplied content. Further analysis is needed to confirm if this issue is relevant and poses a risk to the environmen

CVE advisoryCRITICAL

CVE-2026-16363

Firefox JavaScript WebAssembly Miscompilation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's JavaScript and WebAssembly component due to JIT miscompilation, potentially allowing attackers to execute arbitrary code. This issue was addressed in Firefox 153 and Firefox ESR 140.13, but readers should confirm their exposure to the affected technology and the relevance of

CVE advisoryCRITICAL

CVE-2026-16360

Firefox Memory Corruption Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory safety flaws in Firefox allow for potential arbitrary code execution if exploited. This vulnerability is externally accessible over the network and does not require special privileges or user interaction to exploit. This could impact the confidentiality, integrity, and availability of user systems and data.

CVE advisoryCRITICAL

CVE-2026-16359

Audio/Video GMP Boundary Condition Vulnerability in Firefox

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Firefox's Audio/Video GMP component due to incorrect boundary conditions. If reachable, this flaw could potentially impact the confidentiality and integrity of data processed by the component. Confirmation of its relevance within the environment is advised.

CVE advisoryCRITICAL

CVE-2026-16357

Firefox Graphics Component Boundary Condition Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Graphics component of a web browser due to incorrect boundary conditions. This could allow an unauthenticated attacker to execute arbitrary code if a user visits a malicious web page containing specially crafted content, potentially compromising system and user data.

CVE advisoryCRITICAL

CVE-2026-16355

Firefox JavaScript Engine JIT Miscompilation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's JavaScript engine related to JIT miscompilation. If exploited, this flaw could lead to the compromise of affected systems. Leadership should be aware of this critical issue impacting widely used software.

CVE advisoryCRITICAL

CVE-2026-16353

Firefox Invalid Pointer in DOM Bindings Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's DOM Bindings component, allowing unauthenticated attackers to execute arbitrary code via a malicious website. This could lead to a compromise of confidentiality, integrity, and availability. Security teams should identify affected devices and plan software updates.

CVE advisoryCRITICAL

CVE-2026-16352

Firefox Disability Access APIs Use-After-Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in browser Disability Access APIs could allow attackers to escape the sandbox. This flaw, a use-after-free condition, could potentially affect system data integrity and confidentiality if reachable, but the specific component's local integration suggests limited exposure.

CVE advisoryCRITICAL

CVE-2026-16351

Firefox DOM Navigation Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the browser's DOM:Navigation component that could allow an attacker to escape the security sandbox. This could potentially lead to unauthorized access if a user visits a malicious website. This issue is relevant to the technology used in our environment.

CVE advisoryCRITICAL

CVE-2026-16350

Firefox cubeb Audio/Video Boundary Condition Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Firefox's audio/video component, allowing for potential confidentiality, integrity, and availability impacts. Exploitation requires user interaction with specific content or websites. Leaders should confirm relevance and exposure within their environment.

CVE advisoryCRITICAL

CVE-2026-65008

Grav Blueprint DynamicData Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Grav CMS has a remote code execution vulnerability in Blueprint::dynamicData() that could allow an authenticated user to plant a malicious directive in a page. Accessing that page, even by unauthenticated visitors, would execute the command as the web server user, potentially impacting the integrity and availability of

CVE advisoryCRITICAL

CVE-2026-1617

Turkhotspot 5651 Loglama SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical SQL injection vulnerability exists in Turkmesh Turkhotspot 5651 Loglama, allowing unauthenticated attackers to manipulate database commands over the network. This could lead to unauthorized access, modification, or disclosure of sensitive information. Confirmation of product usage within the environment is n

CVE advisoryCRITICAL

CVE-2026-64606

Apache Fory Lambda Deserialization Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A deserialization vulnerability in Apache Fory allows bypassing Java lambda deserialization checks, potentially impacting lambda capture classes. This could lead to unauthorized actions if the vulnerable component processes untrusted data. Assess its relevance in your environment.

CVE advisoryCRITICAL

CVE-2026-64608

Apache Fory C++ Deserialization Type Confusion Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap type confusion vulnerability exists in the C++ implementation of Apache Fory, a data serialization library. This flaw allows for out-of-bounds memory access when processing inconsistent data schemas during deserialization. It may impact the confidentiality, integrity, and availability of systems using this speci

CVE advisoryCRITICAL

CVE-2026-62415

Joomla Membership Pro Unauthenticated Media Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Joomla Membership Pro extension allows unauthenticated users to upload media assets, potentially enabling the upload of malicious files. This could impact website integrity and availability. Confirming usage of the extension and assessing exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-13439

Easy Form Builder WordPress Plugin Unauthenticated Administrator Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Easy Form Builder WordPress plugin has a critical vulnerability allowing unauthenticated users to escalate privileges to administrator. This is possible by exploiting the password recovery flow to reset any user's password and gain full administrative control of the WordPress site.