NVD disclosure day

Published threat advisories for July 25, 2026

CVE advisoryCRITICAL

CVE-2026-66012

SiYuan Missing Authorization Administrator Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing authorization vulnerability in SiYuan's POST /mcp kernel endpoint allows unauthenticated remote attackers to gain administrator control. This occurs when the Publish server is enabled anonymously, enabling attackers to extract credentials, manipulate files, and deploy malicious plugins for system takeover.

CVE advisoryCRITICAL

CVE-2026-64523

Linux Kernel Netlink Handshake File Reference Issue.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in the Linux kernel's network handshake interface allows for the premature termination of network sockets due to improper file reference management. If reachable, this could impact service stability. Readers should care because it relates to core operating system networking functions.

CVE advisoryCRITICAL

CVE-2026-64459

Linux Kernel TCP Race Condition in tcp_ao_destroy_sock

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's TCP implementation could allow an unprivileged local attacker to trigger a race condition, potentially leading to system crashes or memory corruption. This issue arises from improper handling of RCU grace periods during socket destruction, impacting TCP security features. The vulne

CVE advisoryCRITICAL

CVE-2026-64410

Linux Kernel netfilter Flowtable IPIP Tunnel Hardware Offload Not Supported.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's netfilter component means hardware offload for IPIP tunnels is not supported, potentially causing system instability if attempted. This issue could affect network traffic processing on affected systems.

CVE advisoryCRITICAL

CVE-2026-64399

Linux Kernel ksmbd File Overwrite Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's file-sharing component allows overwriting destination file data due to missing permission checks. If reachable, this could lead to unauthorized data modification, impacting data integrity. Understanding if your environment utilizes this file-sharing functionality is key.

CVE advisoryCRITICAL

CVE-2026-64397

Linux Kernel ksmbd Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's ksmbd component could allow an attacker to crash the system or potentially gain elevated privileges. This use-after-free flaw occurs due to how concurrent directory access requests are handled. While critical, its exploitability depends on the exposure of SMB services.

CVE advisoryCRITICAL

CVE-2026-64393

Linux Kernel SMB Vulnerability Allows Unauthorized Information Modification

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's SMB server (ksmbd) could allow unauthorized file information modification. This flaw arises from incorrect credential handling during specific SMB2 SET_INFO requests, potentially enabling attackers to bypass access controls. While the issue is resolved, organizations should assess

CVE advisoryCRITICAL

CVE-2026-64392

Linux Kernel ksmbd use-after-free vulnerability allows privilege bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Linux kernel's SMB server (ksmbd) could permit unauthorized file deletion by bypassing filesystem permission checks. This occurs during file handle teardown, where operations may incorrectly use server credentials, potentially impacting data integrity and availability. Readers should verify if th

CVE advisoryCRITICAL

CVE-2026-64391

Linux Kernel ksmbd Alternate Data Stream Credentials Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Linux kernel's ksmbd component, which handles SMB file sharing. This issue could allow unauthorized access to or modification of alternate data streams due to incorrect handling of file access credentials. While typically used internally, misconfigurations could lead to external exposure,

CVE advisoryCRITICAL

CVE-2026-64387

Linux Kernel SMB Client Double-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client allows a double-free error when processing directory query responses, potentially causing system instability. This issue is reachable via network, but its relevance depends on whether the SMB client functionality is actively used within an environment.

CVE advisoryCRITICAL

CVE-2026-64386

Linux Kernel SMB Client Double Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Linux kernel's SMB client can lead to a double-free error when a replayable error response is encountered, potentially causing system instability or compromise. This vulnerability affects network file sharing functionality and has been resolved.

CVE advisoryCRITICAL

CVE-2026-64385

Linux Kernel SMB Client Double-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A double-free vulnerability in the Linux kernel's SMB client could allow attackers to crash systems or potentially gain unauthorized access via crafted network packets. This issue affects the kernel's handling of SMB2 ioctl operations. Uncertainty exists regarding the specific products and versions impacted, as well as

CVE advisoryCRITICAL

CVE-2026-64384

Linux Kernel SMB Client Double Free Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client could lead to a double-free condition, potentially impacting system stability. While rated critical, its direct impact is considered very unlikely, but readers should confirm if their systems use this specific kernel feature.

CVE advisoryCRITICAL

CVE-2026-64383

Linux Kernel SMB Client Double-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client could allow for system instability or potential compromise due to a double-free memory error during certain file transfer operations. This occurs when response buffers are not properly reinitialized during retry attempts, potentially leading to memory corruption. While t

CVE advisoryCRITICAL

CVE-2026-64355

Linux Kernel BPF Fragmented Frame Handling Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Linux kernel vulnerability in handling fragmented network frames in devmap could lead to out-of-bounds memory access. This issue, stemming from incorrect packet cloning for fragmented frames in XDP, may cause system instability or data corruption if triggered by specially crafted network packets.

CVE advisoryCRITICAL

CVE-2026-64320

Linux Kernel nvmet Pre-auth Heap Read Leads to Information Disclosure or Denial of Service.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the Linux kernel's NVMe Target (nvmet) subsystem that allows unauthenticated network access to kernel memory. This could lead to information disclosure or system crashes if a specially crafted request is processed.

CVE advisoryCRITICAL

CVE-2026-64303

Linux Kernel SPI Driver Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SPI driver can cause memory corruption or use-after-free if a transmission preparation fails, leaving a receive channel open. This could occur if an error path mishandles DMA channel termination, potentially allowing data to be written to unmapped memory.

CVE advisoryCRITICAL

CVE-2026-64269

Linux Kernel RDMA Write Length Bypass Disclosure Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA/RTRS server allows a remote peer to craft messages that cause data transfers to exceed designated memory boundaries. This could lead to the disclosure of host memory or a connection fault, depending on the system's IOMMU configuration.

CVE advisoryCRITICAL

CVE-2026-64268

Linux Kernel RDMA Out-of-Bounds Write Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA/siw component allows a remote attacker with an established connection to write data out of bounds by sending oversized read response segments. This could lead to system instability or data corruption, and exploitation is possible over routable TCP connections without local pri

CVE advisoryCRITICAL

CVE-2026-64257

Linux Kernel SMB Client Data Area Overlap Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the Linux kernel's SMB client that could allow for the acceptance of malformed responses due to overlapping data areas. This could potentially lead to unexpected system behavior affecting data integrity and availability for systems using the SMB protocol for network file sharing. While the thr

CVE advisoryCRITICAL

CVE-2026-16766

Catalyst::View::Wkhtmltopdf Perl Module Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Catalyst::View::Wkhtmltopdf for Perl allows for remote code execution by injecting shell commands through unsanitized PDF render options. Reachable via web applications that generate PDFs, this flaw poses a significant risk, especially as the underlying wkhtmltopdf project is no longer maint