NVD disclosure day

Published threat advisories for July 24, 2026

CVE advisoryCRITICAL

CVE-2026-61884

Tycon TPDIN-Monitor-WEB2 Unauthenticated Remote Admin Session Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Tycon Systems TPDIN-Monitor-WEB2 web management interface allows unauthenticated remote attackers to bypass login by submitting empty credentials. This grants administrative access, potentially enabling attackers to disrupt connected infrastructure or cause physical damage to equipment by control

CVE advisoryCRITICAL

CVE-2026-64232

Linux Kernel Integrity Segment Accounting Flaw

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's block layer could allow for system instability or crashes in environments using specific stacked storage configurations. This occurs due to incorrect accounting of data integrity segments during cloned request processing. Confirmation is needed on whether affected configurations ar

CVE advisoryCRITICAL

CVE-2026-58630

Azure App Service Improper Access Control Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Improper access control in Azure App Service, a cloud service for hosting web applications, can allow an unauthorized attacker to elevate privileges over a network. This vulnerability, rated critical, could lead to significant unauthorized access and control if exploited. The potential for this service to be internet-f

CVE advisoryCRITICAL

CVE-2026-58586

Image::WebP for Perl Bundles Vulnerable libwebp Version

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Image::WebP module for Perl contains a vulnerable, bundled version of the libwebp library, which is not updated by system patches. Processing untrusted WebP images through this module could lead to code execution, and readers should care because system updates do not fix this issue.

CVE advisoryCRITICAL

CVE-2026-56163

Azure Kubernetes Service Missing Authentication Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in Microsoft Azure Kubernetes Service allows unauthenticated network access to elevate privileges, potentially affecting service integrity and availability. This vulnerability, classified as externally reachable, warrants attention due to the potential for unauthorized privilege escalation.

CVE advisoryCRITICAL

CVE-2026-16634

TOML::XS Stack Overflow Vulnerability via Unmaintained Tomlc99

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in TOML::XS for Perl due to its use of the unmaintained tomlc99 library, which has an uncontrolled recursion flaw. Processing untrusted TOML data could trigger a stack overflow, potentially causing a denial-of-service condition. Its relevance depends on whether applications use this library to pa

CVE advisoryCRITICAL

CVE-2026-24727

SUNNET Training System Arbitrary Command Execution via Unrestricted File Upload

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unrestricted file upload vulnerability in the SUNNET Corporate Training Management System's e-paper draft upload function allows authenticated administrators to execute arbitrary commands by uploading a malicious ZIP archive. This could lead to unauthorized control of the system if the vulnerability is reachable.

CVE advisoryCRITICAL

CVE-2026-15704

Eclipse BaSyx Go Components Authorization Bypass via Trailing Slash Ambiguity

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Eclipse BaSyx Go Components have an authorization bypass vulnerability where inconsistent trailing slash handling between the HTTP router and ABAC middleware can allow unauthenticated attackers to access protected API routes, potentially enabling unauthorized data operations. This issue affects ABAC-enabled deployments

CVE advisoryCRITICAL

CVE-2026-12877

Project Management Bug and Issue Tracking Plugin SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in a WordPress plugin for project management and issue tracking, allowing unauthenticated attackers to inject malicious SQL code into database queries. If this plugin is used and exposed via its front-end issue tracker, attackers could potentially access or modify sensitive

CVE advisoryCRITICAL

CVE-2026-62825

Azure Key Vault Improper Authentication Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper authentication vulnerability in Azure Key Vault allows unauthorized network access to elevate privileges. This could impact the confidentiality and integrity of sensitive information managed by the service. It is uncertain if this issue is relevant or exposed in your environment.

CVE advisoryCRITICAL

CVE-2026-58275

Azure DNS Missing Authorization Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Azure DNS, caused by missing authorization, allows unauthorized attackers to elevate privileges over a network, potentially impacting DNS integrity and management. This exposure in a public-facing cloud service requires immediate confirmation of relevance and exposure within our environment.

CVE advisoryCRITICAL

CVE-2026-56191

Microsoft Exchange Online Improper Authentication Tampering Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Online has a critical improper authentication vulnerability. An unauthorized attacker could tamper with data over a network, potentially impacting service integrity. Organizations should verify their exposure to this cloud-based communication service.

CVE advisoryCRITICAL

CVE-2026-56165

Microsoft Account Heap Overflow Allows Network Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A heap-based buffer overflow in Microsoft Account services could allow an unauthorized attacker to execute code remotely. This affects a public-facing identity portal, potentially impacting system integrity and confidentiality. Determining relevance and exposure is key.

CVE advisoryCRITICAL

CVE-2026-54120

Microsoft Surface Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Microsoft Surface devices have an improper input validation vulnerability allowing an authorized attacker to execute code over a network, potentially impacting system confidentiality, integrity, and availability. Organizations should confirm if their Surface devices are relevant and exposed to this threat.

CVE advisoryCRITICAL

CVE-2026-50517

M365 Copilot Code Execution via Untrusted Data Deserialization.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical deserialization vulnerability in M365 Copilot could permit an authorized attacker to execute arbitrary code over a network. This presents a significant risk to system data, integrity, and availability, requiring immediate attention to confirm exposure and plan remediation.