NVD disclosure day

Published threat advisories for July 22, 2026

CVE advisoryCRITICAL

CVE-2026-60372

Oracle Platform Security for Java Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Platform Security for Java allows unauthenticated network attackers to achieve complete system takeover. This could impact confidentiality, integrity, and availability. Confirming relevance and assessing network exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-60367

Oracle Platform Security for Java Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Platform Security for Java allows unauthenticated attackers with network access to take over the affected system. This issue impacts Oracle Fusion Middleware and could lead to significant confidentiality, integrity, and availability consequences.

CVE advisoryCRITICAL

CVE-2026-60366

Oracle Platform Security for Java Critical Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Platform Security for Java (part of Oracle Fusion Middleware) that allows unauthenticated attackers with network access to compromise the product, potentially leading to a complete takeover and impacting other Oracle products.

CVE advisoryCRITICAL

CVE-2026-64798

Joomla IP Login Extension Persistent URL Key Generation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension that generates persistent URL login keys using weak randomness, potentially allowing unauthorized access. This issue impacts systems using the extension for IP-based logins, where attackers could discover or guess these predictable keys. Understanding this threat is

CVE advisoryCRITICAL

CVE-2026-64793

Joomla Extensions Vulnerable to Content Access Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain Joomla content management extensions have a vulnerability that could allow unauthorized access to restricted or unpublished content. This occurs when content tags incorrectly handle access controls, potentially exposing sensitive information to website visitors. This matters because it could lead to unintended

CVE advisoryCRITICAL

CVE-2025-50329

Power Archiver Privilege Escalation and Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Power Archiver allows remote attackers to escalate privileges and execute arbitrary code via powerarc.exe. This could lead to a compromise of affected systems if a specially crafted file is opened. Organizations should verify if this software is in use and understand its potential exposure.

CVE advisoryCRITICAL

CVE-2026-64829

Question2Answer Session Invalidation via Password Reset.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A session invalidation vulnerability exists in Question2Answer software. Attackers who obtain a valid "remember-me" cookie can exploit the password reset flow to maintain authenticated access. This occurs because the software fails to clear the session code during the reset process, allowing the old cookie to continue

CVE advisoryCRITICAL

CVE-2026-13072

MongoDB Compute Mode Memory Corruption Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A memory corruption vulnerability exists in standalone `mongod` instances when a non-default compute mode is explicitly enabled. This flaw could lead to process termination or unintended behavior if an attacker can provide specially crafted BSON data. Understanding if this specific configuration is active in your envir

CVE advisoryCRITICAL

CVE-2026-16624

Cal.com OSS Webhook Team ID Creation Vulnerability Allows Data Theft.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Cal.com OSS permits authenticated users to create webhooks for any team, potentially exposing sensitive booking data like attendee emails and custom responses, and even video-call passwords. This could lead to data theft and compromise system integrity.

CVE advisoryCRITICAL

CVE-2026-16606

Fujitsu openFT Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Fujitsu Software's openFT technology for Linux and Oracle Solaris that permits unauthenticated remote code execution. This means an attacker could run unauthorized commands on affected systems without needing credentials, if the technology is reachable. Organizations should confirm if they use

CVE advisoryCRITICAL

CVE-2026-2395

Xpoda No Code Platform SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a no-code platform, enabling attackers to execute arbitrary SQL commands without authentication. This could lead to unauthorized access, modification, or deletion of sensitive data, potentially impacting the integrity and availability of applications built with the platform. The

CVE advisoryCRITICAL

CVE-2026-62144

Check Point Management Server Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in Check Point Security Management products, enabling unauthenticated remote attackers to execute administrative commands. This could lead to command execution on management servers and potentially on connected security gateways if the server is network-accessible without a

CVE advisoryKnown Exploit

CVE-2026-16232

Check Point SmartConsole Authentication Bypass Allows Full Administrative Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication bypass vulnerability in Check Point SmartConsole allows unauthenticated remote attackers to gain full administrative access, enabling modification of security policies. Exploitation requires internet access to the Management Server and a specific configuration. This vulnerability is being actively exp

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-8152

Unblu Spark Open Redirect to DOM XSS in Embedded Deployments

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Unblu Spark has a vulnerability that allows open redirects, which can be escalated to DOM-based cross-site scripting (XSS). If exploited, an attacker could execute malicious JavaScript within your host application, potentially accessing sensitive data and resources. This risk is rated critical for on-premises deploymen

CVE advisoryCRITICAL

CVE-2026-63048

Joomla Page Builder CK Arbitrary File Upload Leads to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Joomla extension Page Builder CK that allows authenticated users to upload arbitrary files, potentially leading to remote code execution. This could compromise the integrity and availability of the Joomla site and its infrastructure if the extension is in use and reachable.