NVD disclosure day

Published threat advisories for July 23, 2026

CVE advisoryCRITICAL

CVE-2026-42933

IntraVUE Proxy Vulnerability Bypasses OT Segmentation.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Pronetiqs IntraVUE allows an attacker to bypass network segmentation using an active proxy. This could enable unauthorized access to Operational Technology (OT) systems. The issue is relevant if this software is in use within your environment and requires confirmation of its presence.

CVE advisoryCRITICAL

CVE-2026-28698

Pronetiqs IntraVUE Sensitive Information Exposure Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Pronetiqs IntraVUE that may expose sensitive system information and underlying file system data to unauthorized parties. While the product is an industrial network monitoring solution, its specific deployment and network reachability are not fully detailed, making the potential impact uncertai

CVE advisoryCRITICAL

CVE-2026-63732

9router Default Password and Host Header Bypass Lead to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in 9router, a network routing and management application, allows unauthenticated remote attackers to execute arbitrary code on the host operating system. This is achieved by exploiting a hardcoded default password, bypassing network restrictions via a spoofed host header, and then registering a

CVE advisoryCRITICAL

CVE-2025-71389

Cal.com Unauthenticated Remote Code Execution via Next.js RSC Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cal.com is vulnerable to unauthenticated remote code execution due to improper handling of server requests in a bundled dependency. Attackers can send specially crafted requests to execute arbitrary code on the server, potentially impacting service availability and integrity.

CVE advisoryCRITICAL

CVE-2024-58355

Cal.com Stored Cross-Site Scripting in Booking Questions

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stored cross-site scripting vulnerability exists in Cal.com's booking question feature, allowing attackers to inject malicious code into booking labels. This code can execute when a victim accesses a crafted booking URL, potentially impacting user sessions or data.

CVE advisoryCRITICAL

CVE-2024-58353

Cal.com Booking View Cross-Site Scripting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cal.com's booking view is vulnerable to cross-site scripting when displaying booking question labels, allowing attackers to inject malicious scripts that execute when a victim visits a booking link. This vulnerability, particularly relevant for self-hosted instances with open registration, could lead to the exposure of

CVE advisoryCRITICAL

CVE-2026-52439

Beetl Type New Function Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the xiandafu beetl template engine allows remote attackers to execute arbitrary code via its type.new function. If reachable, this could lead to system compromise, data exposure, and impact Java applications embedding the library, necessitating verification of usage and potential exposure.

CVE advisoryCRITICAL

CVE-2026-49035

Heap Buffer Overflow in MMS Initiate Request Allows Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap-based buffer overflow vulnerability exists in systems handling MMS Initiate requests, allowing remote attackers to potentially execute code or cause denial of service. Exploitation requires network access and sending a crafted request. Memory corruption or remote code execution may occur, particularly if address

CVE advisoryCRITICAL

CVE-2026-47724

Nebula-Mesh API Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the nebula-mesh self-hosted control plane allows an operator with an API key to gain broad cross-tenant access due to insufficient authorization checks on certain API endpoints. This could lead to privilege escalation, potentially exposing sensitive information and allowing unauthorized control over

CVE advisoryCRITICAL

CVE-2026-15981

WordPress SAML SSO Plugin Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The SAML Single Sign On plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user. This occurs due to an error in signature verification, which can be exploited by submitting a crafted SAML response. The critical nature of this flaw means that any reacha

CVE advisoryCRITICAL

CVE-2026-15967

Progress MOVEit Transfer Insufficient Session Expiration Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Progress MOVEit Transfer due to insufficient session expiration, potentially allowing unauthorized network access to data. Organizations using this file transfer solution should verify its exposure and business criticality to prioritize remediation.

CVE advisoryCRITICAL

CVE-2026-15966

Progress MOVEit Transfer Permissive Security Policy Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in Progress MOVEit Transfer due to a permissive cross-domain security policy, potentially allowing untrusted domains to interact with the system. This could lead to unauthorized access, modification, or deletion of data. Confirmation of affected versions and exposure is needed.

CVE advisoryCRITICAL

CVE-2026-15630

Casdoor Authorization Bypass Allows Cross-Tenant Resource Manipulation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists where a non-global administrator in one tenant can bypass security to delete, create, or modify resources in any other tenant. This occurs due to a mismatch in authorization checks, potentially impacting data integrity and availability across the entire platform. This issue is relevant t

CVE advisoryCRITICAL

CVE-2026-10697

Progress MOVEit Transfer Improper Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper authentication vulnerability exists in Progress MOVEit Transfer, a managed file transfer solution. If reachable, this flaw could permit unauthorized access, potentially leading to data compromise and service disruption. Understanding if your organization utilizes this technology is crucial for assessing pot

CVE advisoryCRITICAL

CVE-2026-63359

Appriss Insights VINE Unauthenticated Account Takeover and PII Disclosure.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Appriss Insights VINE applications allows unauthenticated attackers to bypass login, access other users' credentials, and obtain sensitive PII and database information. This could lead to account takeover and data exfiltration. Confirming system relevance and potential exposure is crucial fo

CVE advisoryCRITICAL

CVE-2026-47670

DbGate RCE via unsanitized `functionName` parameter.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

DbGate, a database management tool, has a critical vulnerability that allows authenticated users to execute arbitrary operating system commands with root privileges. This occurs by exploiting an unsanitized `functionName` parameter in a specific endpoint, enabling unauthorized system access and control if an attacker o

CVE advisoryCRITICAL

CVE-2026-47669

DbGate Directory Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in DbGate's file extraction process could allow an attacker to write files anywhere on the filesystem. This occurs when handling ZIP archives without sufficient path validation. In default Docker deployments, this flaw is exploitable remotely without authentication and could impact system integrity.

CVE advisoryCRITICAL

CVE-2026-6516

ManageEngine ADAudit Plus Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ManageEngine ADAudit Plus enables unauthenticated remote code execution via its agent API, potentially allowing attackers to compromise system confidentiality, integrity, and availability without credentials.

CVE advisoryCRITICAL

CVE-2026-65701

SoftVC VITS Singing Voice Conversion Path Traversal Leading to Arbitrary File Read and Write.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in SoftVC VITS Singing Voice Conversion allows unauthenticated remote attackers to read and write arbitrary files on the server via specially crafted requests to the audio processing function. This could lead to sensitive data exfiltration or unauthorized file creation.

CVE advisoryCRITICAL

CVE-2026-65700

h2oGPT Path Traversal Vulnerability Allows Arbitrary File Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability exists in h2oGPT's OpenAI-compatible files API. Unauthenticated remote attackers can exploit this to read, write, or delete arbitrary files on the server by manipulating the bearer token. This could potentially lead to remote code execution.

CVE advisoryCRITICAL

CVE-2026-47752

Tugtainer SSTI Allows Arbitrary Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Tugtainer, a self-hosted Docker container update automation tool, allows authenticated users to execute arbitrary OS commands as root. This is due to unsandboxed template rendering, which could lead to a full container compromise if the notification feature is used. Critical administrative tools like

CVE advisoryCRITICAL

CVE-2026-47668

DbGate Remote Code Execution via JSON Script Runner.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the DbGate database management tool allows remote code execution via code injection in the `functionName` parameter. If reachable, an attacker could exploit this to compromise the affected system. Readers should care to identify if this tool is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-65760

Joomla Easy Store Information Disclosure Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a Joomla e-commerce extension allows logged-in users to access any customer's order and personal information due to improper access checks. This could expose sensitive data across different users, impacting e-commerce operations and customer trust.

CVE advisoryCRITICAL

CVE-2026-15617

Logto Account Takeover Vulnerability via Unnormalized Identifiers.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Logto, an identity and access management system, allows attackers to gain unauthorized account access by exploiting the improper normalization of email and identifier strings. This principal collision occurs when differing character casing or Unicode representations are treated as the same identity,

CVE advisoryCRITICAL

CVE-2026-15616

Logto SSO MFA Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Logto allows bypassing multi-factor authentication during single sign-on, granting unauthorized access and potentially exposing system or user data. This issue could compromise account integrity and requires attention to ensure proper authentication controls are in place.

CVE advisoryCRITICAL

CVE-2026-15612

Logto OIDC nonce validation bypass allows token replay

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Logto allows authentication tokens to be replayed by bypassing OpenID Connect nonce validation, particularly when the nonce claim is absent from the ID token. This could weaken user session security and grant unauthorized access. Readers should care because this issue impacts identity and access mana

CVE advisoryCRITICAL

CVE-2026-15611

Logto Unverified Email SSO Account Linking Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Logto's identity management technology has a vulnerability where unverified email-based SSO account linking can allow an attacker to gain unauthorized access to a victim's account by registering an identity with a permissive identity provider using the victim's email. This could lead to unauthorized access to account a

CVE advisoryCRITICAL

CVE-2026-65689

Bold Reports Designer Arbitrary File Read via Database Download.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Bold Reports Standalone Report Designer allows unauthenticated attackers to read arbitrary server files, including credentials, via a crafted request to the database download feature. This could lead to unauthorized access to the application.

CVE advisoryCRITICAL

CVE-2026-65688

Bold Reports Standalone Report Designer Arbitrary File Read via Font Processing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing filepath validation vulnerability in Bold Reports Standalone Report Designer's font processing feature allows unauthenticated attackers to read arbitrary server files via a crafted request. This path traversal weakness can expose sensitive information like authentication credentials, potentially leading to un

CVE advisoryCRITICAL

CVE-2026-65687

Bold Reports Designer SVG Path Traversal Arbitrary File Read

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Bold Reports Standalone Report Designer has a vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server. This path traversal weakness can lead to the disclosure of sensitive server files, potentially enabling unauthorized access to the application. You sho

CVE advisoryCRITICAL

CVE-2026-65907

JetBrains TeamCity Git VCS Root Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical code execution vulnerability exists in JetBrains TeamCity, allowing attackers to run unauthorized commands through Git repositories. This could compromise the TeamCity server's integrity and availability, potentially exposing sensitive data. Confirming if TeamCity is deployed and assessing its network exposu

CVE advisoryCRITICAL

CVE-2026-65606

SiYuan Protocol Handler Vulnerability Leads to Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A cross-site scripting vulnerability in the SiYuan desktop application's protocol handler allows for arbitrary operating system command execution if a user clicks a malicious link. This could lead to unauthorized commands running on user machines.

CVE advisoryCRITICAL

CVE-2026-65605

SiYuan Stored XSS to RCE in Attribute View.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A stored cross-site scripting vulnerability in SiYuan's Attribute View can allow arbitrary command execution if a user views a crafted database cell. This occurs because a template column value is rendered as HTML without proper escaping, enabling malicious scripts to execute and potentially take control of the user's

CVE advisoryCRITICAL

CVE-2026-65471

Avada Core Cross-Site Request Forgery Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in Avada Core. This flaw could enable an attacker to trick authenticated users into performing unintended actions on a web application by interacting with malicious content. The reachability of this technology on internet-facing systems warrants

CVE advisoryCRITICAL

CVE-2026-65461

Really Simple CSV Importer Arbitrary File Upload Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical arbitrary file upload vulnerability exists in a WordPress plugin, potentially allowing an authenticated administrator to upload malicious files and gain system control. Confirmation of plugin usage and administrative access security is advised.

CVE advisoryCRITICAL

CVE-2026-64815

IntelliJ IDEA Code Injection via UI Designer Form Files.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

JetBrains IntelliJ IDEA contains a critical vulnerability allowing arbitrary code injection through UI Designer form files. If reachable, this could impact the integrity of development environments, though its likelihood is currently assessed as very unlikely given the tool's local use. Confirmation of affected version

CVE advisoryCRITICAL

CVE-2026-64813

IntelliJ IDEA Remote Development Unauthorized Settings Modification

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in JetBrains IntelliJ IDEA could allow unauthorized modification of settings during Remote Development sessions. If reachable, an unauthenticated attacker could alter application settings, potentially impacting the integrity and availability of the development environment. This issue requires a

CVE advisoryCRITICAL

CVE-2026-64812

JetBrains IntelliJ IDEA Remote Development Unauthorized Input Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated input injection vulnerability exists in JetBrains IntelliJ IDEA Remote Development sessions. If reachable, this could allow an attacker to inject unauthorized input into a remote session. This issue is relevant if your organization utilizes this feature.

CVE advisoryCRITICAL

CVE-2026-61951

TrueBooker Unauthenticated Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in TrueBooker, potentially allowing attackers to gain elevated privileges. This could lead to unauthorized access and modification of data and services. Confirming the use and exposure of this software is crucial to understanding its relevance.

CVE advisoryCRITICAL

CVE-2026-61950

TrueBooker Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in TrueBooker's appointment booking functionality, potentially allowing unauthorized access to sensitive data. It's important to determine if your organization uses this software to assess potential exposure and risk. The vulnerability is reachable via the network,

CVE advisoryCRITICAL

CVE-2026-61949

Bookly SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Bookly booking plugin. Attackers can exploit this by sending malicious requests, potentially leading to unauthorized data access or service disruption. The main concern is to confirm if this technology is in use and assess its exposure.

CVE advisoryCRITICAL

CVE-2026-61948

WPDM Premium Packages SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WPDM – Premium Packages WordPress plugin, potentially allowing attackers to access sensitive database information. Because the vulnerability is network-accessible, it may be reachable by external attackers. Confirming the use of this plugin is crucial to asse

CVE advisoryCRITICAL

CVE-2026-59555

Participants Database Unauthenticated Arbitrary File Deletion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated arbitrary file deletion vulnerability exists in Participants Database. This means an attacker could delete files without logging in, potentially causing data loss or system disruption. You should care because this critical vulnerability is network-accessible and could impact your organization's data

CVE advisoryCRITICAL

CVE-2026-59543

Advanced Views Plugin Subscriber Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Advanced Views allows a subscriber to execute remote code. This could lead to a compromise of the application's integrity and confidentiality. The primary concern is to confirm if this component is in use within your environment.

CVE advisoryCRITICAL

CVE-2026-59540

SMS Alert Order Notifications Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in SMS Alert Order Notifications. This critical flaw could allow an unauthenticated attacker to gain elevated control over systems using the affected technology. The potential for unauthorized administrative access poses a significant risk to system integrity

CVE advisoryCRITICAL

CVE-2026-59526

MapSVG SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in MapSVG, a mapping plugin for websites. This flaw could allow attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data or service disruption. The primary concern is to identify if this plugin is used and assess the ass

CVE advisoryCRITICAL

CVE-2026-59525

Participants Database Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Participants Database plugin, potentially allowing attackers to access sensitive database contents without prior authentication. This could lead to unauthorized information disclosure when the plugin is internet-facing. Confirming its usage and exposure is cr

CVE advisoryCRITICAL

CVE-2026-59514

BuddyBoss Platform SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Buddyboss Platform, potentially allowing attackers to access sensitive data by sending specially crafted requests. This issue is relevant to systems using the Buddyboss Platform, and further assessment is needed to determine specific exposure and impact.

CVE advisoryCRITICAL

CVE-2026-57784

Ninja Forms File Uploads Unauthenticated CSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Cross-Site Request Forgery vulnerability exists in the Ninja Forms File Uploads Extension, allowing unauthenticated attackers to force users to perform unintended actions. This could lead to unauthorized file uploads or modifications on affected websites.

CVE advisoryCRITICAL

CVE-2026-27064

Mailster Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Mailster plugin, allowing authenticated attackers to upload arbitrary files. This could potentially lead to unauthorized code execution and impact system integrity and availability. Confirming its presence and reachability is advised.

CVE advisoryCRITICAL

CVE-2026-65431

Joomla GeoIP Extension Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a Joomla extension that allows unsafe file extractions due to a lack of path validation. This could permit attackers to write arbitrary files to the server, potentially impacting the integrity and availability of the Joomla installation and its underlying system. The primary concern is determi

CVE advisoryCRITICAL

CVE-2026-64874

Joomla Extension Exposes CDN Credentials in URLs

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension where CDN credentials are exposed in administrator request URLs. If reachable, this could lead to unauthorized access to sensitive information. Security leaders should confirm the use and exposure of this extension to assess relevance and potential impact.

CVE advisoryCRITICAL

CVE-2026-64873

Joomla Cache Cleaner Pro SSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension, allowing attackers to potentially access internal network services by manipulating query URLs. This Server-Side Request Forgery (SSRF) weakness could enable unauthorized probing or interaction with systems behind firewalls. Understanding the presence and reachabili

CVE advisoryCRITICAL

CVE-2026-15015

MountDev AI MCP Connector Authorization Bypass Leads to Administrator Token Theft.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The MountDev AI MCP Connector for WordPress plugin has an authorization bypass vulnerability. This flaw allows unauthenticated attackers to obtain administrator tokens, granting them full administrative control over WordPress content, users, and options. The vulnerability is exploitable via publicly accessible registra

CVE advisoryCRITICAL

CVE-2026-15011

WordPress Support Ticket Plugin Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A code injection vulnerability exists in a WordPress customer support plugin that allows unauthenticated attackers to execute arbitrary code. This can disrupt site functionality or expose sensitive information. The vulnerability is reachable via a shortcode on public pages, making it a concern for sites using this plug

CVE advisoryCRITICAL

CVE-2026-14282

GoDAM WordPress Plugin Arbitrary File Upload Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the GoDAM WordPress plugin allows unauthenticated attackers to upload arbitrary files to a server by bypassing validation checks. This could lead to remote code execution. Security-aware leaders should confirm if the plugin is in use and assess the associated risks.

CVE advisoryCRITICAL

CVE-2026-16723

Fastjson RCE Vulnerability in versions 1.2.68 through 1.2.83

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the fastjson library, exploitable with default configurations. This means an attacker could potentially run arbitrary code on systems processing JSON if they can reach the vulnerable library, impacting data integrity, availability, and confidentiality. Understand