NVD disclosure day

Published threat advisories for July 27, 2026

CVE advisoryCRITICAL

CVE-2021-32088

Quest KACE SMA API Rate Limiting Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Quest KACE Systems Deployment Appliance allows bypassing API rate limiting by removing a specific cookie. This could enable unauthorized access and potential compromise of the appliance, which is designed for network asset management. The potential impact necessitates confirmation of relevance an

CVE advisoryCRITICAL

CVE-2021-32086

Quest KACE SMA Hardcoded Encryption Key Exposes Secrets.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An issue in Quest KACE Systems Deployment Appliance allows decryption of stored secrets via a hardcoded encryption key if an attacker gains access to the MySQL database or backup files. This could potentially lead to privilege escalation within KACE or unauthorized access to other systems. The exploit requires access t

CVE advisoryCRITICAL

CVE-2021-32084

Quest KACE SMA API Access Despite IP Restrictions

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Quest KACE Systems Deployment Appliance where API endpoints are not restricted, allowing bypass of IP access controls. An attacker with known credentials could compromise the entire managed environment if the appliance is reachable. This is important if your organization uses KACE for

CVE advisoryCRITICAL

CVE-2026-66824

Cross-Site Scripting in Capture Tree Visualization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in a web-based visualization page where attacker-controlled data can be embedded in JavaScript. If reachable, this could allow attackers to execute arbitrary code in a victim's browser, potentially leading to unauthorized actions or data access within their authenticat

CVE advisoryCRITICAL

CVE-2026-64775

Apple Operating System Memory Initialization Flaw Leads to System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory initialization flaw in Apple operating systems may allow an application to unexpectedly terminate the system. While this does not appear to expose data, it could impact device stability and availability. This issue is fixed in the latest OS updates.

CVE advisoryCRITICAL

CVE-2026-64772

iOS and iPadOS Out-of-Bounds Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability in Apple's operating systems may allow a remote attacker to cause unexpected application termination or heap corruption. This issue is addressed with improved input validation in newer versions of iOS, iPadOS, macOS, tvOS, and visionOS. The primary concern is confirming if affected

CVE advisoryCRITICAL

CVE-2026-64771

Buffer Overflow in Apple Operating Systems Leads to Application Termination or Heap Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow vulnerability in Apple operating systems could allow remote attackers to cause application termination or heap corruption. This issue has been fixed in recent software updates. The main concern is confirming if systems are affected and reachable within the environment.

CVE advisoryCRITICAL

CVE-2026-64770

Apple Out-of-Bounds Write Vulnerability Affects Multiple Operating Systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability exists in Apple's operating systems that could allow a remote attacker to cause application termination or heap corruption. While the vulnerability is network-exploitable without user interaction, the primary concern for organizations is to understand its relevance to their specific

CVE advisoryCRITICAL

CVE-2026-64769

Apple OS Out-of-Bounds Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability in Apple operating systems could allow remote attackers to cause application termination or heap corruption. This issue is addressed with improved bounds checking. The remote nature of the exploit means users could be affected by sending crafted data, potentially leading to unexpect

CVE advisoryCRITICAL

CVE-2026-64767

macOS Kernel Buffer Overflow Corrupts Memory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow in macOS can allow a remote attacker to cause unexpected system termination or corrupt kernel memory. This issue affects core operating system components, and the primary concern is to confirm its relevance and exposure within your environment.

CVE advisoryCRITICAL

CVE-2026-64746

Apple OS Contact App Authorization Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An authorization issue in Apple operating systems allows an app to add contacts without user consent. While the vulnerability is fixed in current OS versions, an affected app could potentially add contacts without permission. This could lead to unauthorized access or manipulation of user contact data. Uncertainty exist

CVE advisoryCRITICAL

CVE-2026-64740

Directory Path Parsing Flaw Allows Sandbox Breakout

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A directory path parsing vulnerability has been fixed in operating system updates. This flaw could allow a malicious application to escape its sandbox. The main concern is to identify unpatched systems that may be exposed. <tool_code print(google_search.search(queries=["CVE-2026-64740 affected technology", "CVE-2026-64

CVE advisoryCRITICAL

CVE-2026-64738

macOS Sandbox Breakout Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A permissions flaw in macOS allows a malicious app to break out of its sandbox, potentially accessing unauthorized information or functionality. This issue is relevant for systems running affected macOS versions.A permissions flaw in macOS allows a malicious app to break out of its sandbox, potentially accessing unauth

CVE advisoryCRITICAL

CVE-2026-64733

Apple Platform User Fingerprinting Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Apple's operating systems could allow an app to fingerprint users. This means an app might collect unique user characteristics to identify individuals, potentially enabling tracking and profile building without consent. The issue is addressed in updated operating system versions.

CVE advisoryCRITICAL

CVE-2026-64729

Use After Free in Apple Operating Systems Leads to System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in Apple operating systems could allow an application to cause unexpected system termination, impacting device stability. This issue is addressed in the latest versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Device owners and IT asset management should confirm affected devices and pla

CVE advisoryCRITICAL

CVE-2026-64726

Physical Proximity Memory Corruption in Apple Operating Systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability exists in Apple operating systems that an attacker in physical proximity could exploit. This flaw might allow an attacker to corrupt process memory, potentially leading to unpredictable behavior or instability. The main concern is confirming if affected devices are reachable and releva

CVE advisoryCRITICAL

CVE-2026-64720

Race Condition in Apple Operating Systems Allows Unexpected System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in Apple operating systems could allow an application to cause unexpected system termination. This vulnerability, addressed in recent system updates, is reachable through an installed application, impacting system stability and availability. Confirming your environment's exposure to this issue is advis

CVE advisoryCRITICAL

CVE-2026-64702

macOS Sandbox Breakout Vulnerability Addressed with Enhanced Restrictions

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An access issue in macOS allowed apps to potentially break out of their sandbox restrictions, which has been addressed with enhanced sandbox limitations in macOS updates. This means an application could gain unauthorized access to system data or functionalities if it were to reach or exploit this vulnerability. It is i

CVE advisoryCRITICAL

CVE-2026-64700

Apple Use After Free Vulnerability Leads to Unexpected App Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Apple operating systems allows an app to cause unexpected system termination. This critical issue could impact system stability when an app is running, necessitating a review to confirm relevance and exposure. <br> **Character Count:** 253

CVE advisoryCRITICAL

CVE-2026-64698

Apple macOS Memory Handling Vulnerability Leads to System Termination or Kernel Memory Read.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in macOS that may allow an application to cause unexpected system termination or read kernel memory. This issue has been fixed with improved memory handling in macOS updates. The potential for system instability and unauthorized data access highlights the need to understand its relevance in your

CVE advisoryCRITICAL

CVE-2026-64697

macOS Kernel Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in macOS that could allow an application to cause unexpected system termination or corrupt kernel memory. Improved memory handling has addressed this issue. The potential for system instability and data corruption warrants attention.

CVE advisoryCRITICAL

CVE-2026-64694

macOS Integer Overflow Leads to System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability in macOS may allow an app to cause unexpected system termination. This issue has been addressed with improved input validation in recent updates, and while direct internet exposure is unlikely, the potential for system instability warrants attention.

CVE advisoryCRITICAL

CVE-2026-64691

macOS Tahoe Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow vulnerability in macOS may allow an application to cause unexpected system termination. While the exact conditions for exploitation are not fully detailed, the potential for system instability warrants attention for organizations utilizing macOS.

CVE advisoryCRITICAL

CVE-2026-64551

Linux Kernel SCTP STALE_COOKIE Length Validation Flaw Information Leak

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Linux kernel's SCTP implementation where insufficient validation of a STALE_COOKIE cause length can lead to the leakage of uninitialized memory to a network peer. This flaw is network-reachable by any peer capable of driving an association into the COOKIE_ECHOED state, potentially allowing

CVE advisoryCRITICAL

CVE-2026-64541

Linux Kernel Use-After-Free in SMC Networking

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMC-R networking could lead to a use-after-free error when handling network data. This flaw may allow an attacker to trigger a kernel panic, disrupting services. There is uncertainty about direct data exposure, but system stability could be affected.

CVE advisoryCRITICAL

CVE-2026-43822

Apple Use After Free System Termination Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability impacts Apple operating systems, potentially causing unexpected system termination if exploited by an app. While specific data compromise is not indicated, system stability could be affected, necessitating confirmation of relevance and assessment of exposure.

CVE advisoryCRITICAL

CVE-2026-43814

Apple Use After Free Vulnerability Leads to Unexpected System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical use-after-free vulnerability in Apple operating systems could allow an application to cause unexpected system termination. This issue is addressed with improved memory management. The extent of potential exploitation or system impact beyond unexpected termination is uncertain.

CVE advisoryCRITICAL

CVE-2026-43812

Apple OS Use After Free Vulnerability Leading to System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Apple operating systems may allow an application to cause unexpected system termination. This issue is addressed in updated software. An app could potentially trigger an unexpected system termination, impacting system stability and availability. Confirmation of deployed operating syste

CVE advisoryCRITICAL

CVE-2026-43810

Apple iOS iPadOS macOS tvOS visionOS watchOS Kernel Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Apple operating systems could allow remote attackers to terminate systems unexpectedly or corrupt kernel memory. This memory handling issue is fixed in updated versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

CVE advisoryCRITICAL

CVE-2026-43809

macOS Out-of-Bounds Read Vulnerability in System Components

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds read vulnerability in macOS system components could allow an application to cause unexpected system termination. An app may be able to trigger this by interacting with a vulnerable system component, leading to a system crash. The exact impact on business operations is uncertain.

CVE advisoryCRITICAL

CVE-2026-43805

iOS iPadOS macOS and watchOS Race Condition Allows Kernel Memory Write and Unexpected Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in Apple operating systems could allow a malicious app to cause unexpected system termination or write to kernel memory. This vulnerability does not require special privileges or user interaction to exploit. Although the attack vector is network-based, the issue is within local OS components. Protectin

CVE advisoryCRITICAL

CVE-2026-43803

Apple Operating System Out-of-Bounds Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability exists in Apple operating systems, which could allow a remote attacker to cause unexpected system termination. The relevance and exposure of this issue depend on the specific deployment of these client-side operating systems and consumer devices.

CVE advisoryCRITICAL

CVE-2026-43802

macOS Out-of-Bounds Write Leads to Unexpected System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical out-of-bounds write vulnerability in macOS could allow a reachable application to cause unexpected system termination. This issue impacts system stability and availability. The exact exploitation path and affected data are not specified, but the potential for system instability warrants attention.

CVE advisoryCRITICAL

CVE-2026-43793

macOS Environment Variable Handling Vulnerability Leads to System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An issue exists in macOS environment variable handling that could lead to unexpected system termination. This vulnerability may be triggered by an application, impacting system stability. The problem has been fixed with improved validation in recent macOS updates.

CVE advisoryCRITICAL

CVE-2026-43778

Apple Use After Free Vulnerability Allows Kernel Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Apple operating systems could allow an app to cause unexpected system termination or corrupt kernel memory. This issue is addressed in recent updates for various Apple platforms. The risk is that a malicious app could potentially lead to device instability.

CVE advisoryCRITICAL

CVE-2026-43773

macOS Disk Image Parsing Out-of-Bounds Read Leading to Kernel Memory Corruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in macOS allows for unexpected system termination or kernel memory corruption if a user mounts a maliciously crafted disk image. This out-of-bounds read issue impacts the operating system's disk image handling. While exploitation requires user interaction, the potential for kernel memory corrup

CVE advisoryCRITICAL

CVE-2026-43769

Integer Overflow in Apple Operating Systems Allows Unexpected System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability in Apple's operating systems could allow an application to cause unexpected system termination. This issue has a critical severity rating, indicating a potential for significant disruption if exploited through specially crafted input to an application. Understanding if these operating

CVE advisoryCRITICAL

CVE-2026-43757

macOS Out-of-Bounds Read Allows Unexpected System Termination

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds read vulnerability in macOS system components may allow an application to cause unexpected system termination. This issue is addressed in available updates. The primary concern is confirming if macOS is in use and assessing potential exposure to system stability.

CVE advisoryCRITICAL

CVE-2026-43748

macOS Out-of-Bounds Write Allows Unexpected System Termination.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability exists in macOS, which could allow an application to cause unexpected system termination. This issue impacts system stability and availability. Uncertainty remains regarding specific exploitation paths and their relevance to your environment.

CVE advisoryCRITICAL

CVE-2026-43730

iOS iPadOS macOS tvOS visionOS watchOS Permissions Issue Allows User Fingerprinting

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A permissions issue in Apple operating systems could enable an app to fingerprint users. This vulnerability impacts various Apple devices and has been fixed in recent software updates. The concern is whether this issue is relevant to the environment and if any assets are exposed.

CVE advisoryCRITICAL

CVE-2026-43710

macOS Kernel Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This critical vulnerability in macOS kernel memory handling could allow an unauthenticated attacker to cause system termination or corrupt kernel memory. While the issue is fixed in recent updates, its exploitability via network requests warrants attention for affected systems.

CVE advisoryCRITICAL

CVE-2026-43694

macOS Memory Corruption Vulnerability Allows Kernel Memory Write

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in macOS memory handling could allow a local application to cause unexpected system termination or write to kernel memory. This impacts system integrity and data. Confirmation of affected macOS versions is needed.

CVE advisoryCRITICAL

CVE-2026-39873

macOS SMB Remote Code Execution Vulnerability CVE-2026-39873

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in macOS memory handling could allow an attacker to cause unexpected system termination by tricking a user into connecting to a malicious SMB server. While impactful, this vulnerability's reachability is considered unlikely due to typical network configurations.

CVE advisoryCRITICAL

CVE-2026-28982

macOS Kernel Race Condition Allows System Termination and Kernel Memory Corruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in macOS could allow a remote user to cause unexpected system termination or corrupt kernel memory. This vulnerability is accessible over the network and does not require special privileges or user interaction to trigger. If exploited, it could lead to significant system instability.

CVE advisoryHIGH

CVE-2026-28931

Apple iOS Kernel Memory Corruption via Malicious NFS Server

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A buffer overflow vulnerability in Apple operating systems could allow a malicious NFS server connection to corrupt kernel memory. This could impact system stability and integrity. While the risk is considered unlikely due to typical NFS usage in trusted networks, confirming system exposure is recommended.

CVE advisoryCRITICAL

CVE-2026-28928

Use After Free Vulnerability in Apple Operating Systems

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical use-after-free vulnerability in Apple operating systems could allow an application to cause unexpected system termination. This memory management flaw, if reached, may impact system stability. The exact impact and reachability are currently under analysis.

CVE advisoryCRITICAL

CVE-2026-66014

JFrog Artifactory Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

JFrog Artifactory has an authentication weakness that could allow an attacker to escalate privileges. If this vulnerability is reachable, it may enable unauthorized access to system data and impact service behavior. Confirming the presence and relevance of JFrog Artifactory in your environment is crucial for understand

CVE advisoryCRITICAL

CVE-2026-55579

Pheditor Default Password Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hardcoded default password in Pheditor allows unauthenticated attackers to gain full control over file operations and execute arbitrary code. This vulnerability could lead to unauthorized file access and remote code execution on affected systems.

CVE advisoryCRITICAL

CVE-2026-48030

Pheditor OS Command Injection Vulnerability Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Pheditor, a PHP file manager, has a critical OS command injection vulnerability. Authenticated users can execute arbitrary commands on the web server, potentially leading to full remote code execution. This issue is relevant to organizations using Pheditor for file management. The vulnerability has been patched in vers

CVE advisoryCRITICAL

CVE-2026-17552

Plack App Prerender Allows Arbitrary Host Access via Unvalidated Request URI.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Plack::App::Prerender that allows unvalidated requests to proxy to arbitrary hosts, potentially enabling attackers to access internal or restricted network resources. This could lead to the exposure of sensitive information by redirecting requests to attacker-controlled locations. Confirmation

CVE advisoryCRITICAL

CVE-2026-63077

JetBrains TeamCity Agent Polling Protocol Unauthenticated Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in JetBrains TeamCity allows unauthenticated remote code execution via the agent polling protocol. This could enable attackers to compromise the TeamCity server and its build agents, impacting CI/CD operations.

CVE advisoryCRITICAL

CVE-2026-66398

phpMyFAQ Configuration API Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability exists in the phpMyFAQ configuration API, allowing authenticated administrators to write arbitrary PHP files. If reachable, this could lead to code execution on the web server. Administrators should verify if this technology is in use and confirm relevant access privileges.

CVE advisoryCRITICAL

CVE-2026-66396

SiYuan Stored Cross-Site Scripting Leading to Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in SiYuan's gallery and Kanban features allows stored cross-site scripting, potentially leading to arbitrary code execution. An attacker with editor permissions can inject malicious code into document cover images, which then executes on a victim's system when they open the affected document. T

CVE advisoryCRITICAL

CVE-2026-66395

SiYuan Desktop Bazaar Plugin Reflected XSS to RCE via Siyuan Protocol

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A reflected cross-site scripting vulnerability exists in the SiYuan desktop application's bazaar plugin. Attackers can exploit this by tricking users into clicking malicious `siyuan://` links, potentially leading to arbitrary code execution with full Node.js access. This could compromise user systems if the application

CVE advisoryCRITICAL

CVE-2026-66394

SiYuan Stored and Reflected XSS via SVG Sanitizer Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

SiYuan's SVG sanitization contains vulnerabilities that allow authenticated attackers to execute scripts by bypassing security controls. This could enable script execution within the application's origin when specially crafted SVG files are rendered, potentially leading to unauthorized actions or data compromise. Uncer

CVE advisoryCRITICAL

CVE-2026-55953

Erlang/OTP TLS Client Cipher Suite Selection Bypass

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Erlang/OTP's TLS client allows an attacker to intercept and modify communications by bypassing certificate validation and forcing the use of an anonymous cipher suite. This affects TLS 1.2 and earlier, and DTLS, but not TLS 1.3. The reader should care because this could expose sensitive data in trans

CVE advisoryUNKNOWN

CVE-2026-51303

SQLite Use-After-Free Vulnerability Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability in SQLite's core parsing component can be triggered by specially crafted SQL queries, potentially causing application crashes, sensitive data leakage, or arbitrary code execution. This issue should be concerning because it could impact the integrity and availability of applications utiliz

CVE advisoryUNKNOWN

CVE-2026-51302

SQLite Use-After-Free in Expression Evaluation Leads to Denial of Service or Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in SQLite's expression evaluation logic may allow a remote attacker to cause denial of service, leak sensitive information, or potentially execute arbitrary code by supplying a malicious SQL statement.

CVE advisoryUNKNOWN

CVE-2026-51300

SQLite Use-After-Free Leads to Crash and Information Leak

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free flaw in SQLite allows attackers to crash applications or leak memory via malicious SQL queries. This occurs because the software attempts to access memory after it has been freed. The potential impact includes application crashes and sensitive data exposure.

CVE advisoryKnown Exploit

CVE-2026-16812

VeloCloud Orchestrator Remote Privileged Access Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An on-premise VeloCloud Orchestrator has a vulnerability allowing remote attackers to access privileged internal functions, potentially compromising the orchestrator and its data. This issue is actively exploited, and while cloud versions are patched, on-premise deployments require attention.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-50455

EasyAppointments SQL Injection Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the customer search functionality of EasyAppointments software, allowing attackers to execute arbitrary SQL queries through the `order_by` parameter. This could lead to unauthorized access to sensitive data or, under specific MySQL configurations, remote code execution. Its relev

CVE advisoryCRITICAL

CVE-2026-59550

AWP Classifieds SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in AWP Classifieds. If reachable, an attacker could execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data. Confirmation of affected plugin usage within the environment and assessment of potential exposure are necessary.An unaut

CVE advisoryCRITICAL

CVE-2026-59549

rtMedia for WordPress Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the rtMedia plugin, potentially allowing attackers to access or modify sensitive database information. This issue affects WordPress sites using the plugin for media features and could impact data integrity if exploited. The reachability and business criticality o

CVE advisoryCRITICAL

CVE-2026-59538

GamiPress Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the GamiPress plugin. This could allow an attacker to manipulate database queries, potentially leading to unauthorized access to sensitive information. Organizations should confirm if they use this plugin and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-59533

Relevanssi Light Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Relevanssi Light plugin, allowing unauthenticated attackers to access or modify sensitive data. Because the plugin is network-accessible and often used in public-facing websites, this issue could be reachable by external threats.

CVE advisoryCRITICAL

CVE-2026-65879

SP Page Builder Unauthenticated Mail Relay via Hardcoded Secret

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension, allowing unauthenticated attackers to relay emails through websites by exploiting a hardcoded secret. This enables the forging of sender addresses for forms processed by the extension, potentially impacting email integrity and enabling abuse. Confirming the use and

CVE advisoryCRITICAL

CVE-2026-65876

Joomla SP Page Builder Unauthenticated SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a Joomla extension, allowing attackers to inject malicious SQL code through improper validation of parameters in the `loadMoreArticles` endpoint. This could lead to unauthorized access or modification of sensitive data within the extension's article loading featu

CVE advisoryCRITICAL

CVE-2026-65766

Joomla SP Page Builder Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a Joomla extension, allowing attackers to inject malicious SQL code by exploiting improper validation of order parameters. This could lead to unauthorized access, modification, or deletion of sensitive website data. Confirm relevance to your Joomla sites.

CVE advisoryCRITICAL

CVE-2026-61511

vBulletin Eval Injection RCE via Template Runtime

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical eval injection vulnerability in vBulletin's template runtime allows unauthenticated attackers to execute arbitrary PHP code remotely by supplying crafted input. This impacts the software's public-facing template rendering, potentially enabling broad compromise when reachable.

CVE advisoryCRITICAL

CVE-2026-55971

Apache Thrift C++ Heap Overflow Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap-based buffer overflow vulnerability exists in Apache Thrift's C++ bindings. If reachable, this could allow an attacker to cause a denial-of-service or potentially execute code, impacting service availability and integrity. Confirmation of Thrift's presence and network exposure within your systems is needed to as

CVE advisoryCRITICAL

CVE-2026-48144

Apache Thrift c_glib Host Mismatch Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Thrift's c_glib bindings involves improper certificate validation with host mismatches. This could allow an attacker to impersonate a trusted service, potentially leading to compromised communications and sensitive data exposure. While typically used for internal communication, its relevance r

CVE advisoryMEDIUM

CVE-2026-12495

Mercusys MB115-4G Web Interface Stack Buffer Overflow Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A denial-of-service vulnerability exists in the web administration interface of Mercusys MB115-4G devices, allowing unauthenticated attackers to crash the system by sending a crafted request. This could disrupt the web administration service and make the device's management interface unavailable.

CVE advisoryCRITICAL

CVE-2026-64534

Linux Kernel nvmet-tcp Refcount Underflow Leads to Workqueue Deadlock.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's NVMe-over-TCP driver could allow a remote attacker to cause a system-wide workqueue deadlock. This occurs when a data digest mismatch is detected, leading to a use-after-free condition. While exploitable over the network, its relevance depends on the specific deployment of the NVMe

CVE advisoryCRITICAL

CVE-2026-14289

FacturaONE WooCommerce Plugin Arbitrary File Write Leading to RCE.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the FacturaONE para WooCommerce con VeriFactu WordPress plugin, allowing unauthenticated attackers to write arbitrary files to web-accessible directories and achieve remote code execution. This occurs because a request handler lacks proper authentication, especially in its default, un

CVE advisoryCRITICAL

CVE-2026-13714

Realtyna Organic IDX and WPL Real Estate Plugin Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Realtyna Organic IDX and WPL Real Estate WordPress plugins that allows unauthenticated attackers to upload and execute arbitrary PHP files. This could lead to remote code execution on affected websites. The issue stems from insufficient file type validation and the use of hardcoded API credent

CVE advisoryCRITICAL

CVE-2026-13597

微信二维码登陆 WordPress Plugin Vulnerability Allows Unauthenticated Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WordPress plugin allows unauthenticated attackers to bypass login procedures by forging WeChat webhook requests. This flaw enables attackers to obtain login codes and impersonate any user, including administrators, without a password, posing a significant risk to account security.

CVE advisoryCRITICAL

CVE-2026-13332

Masteriyo LMS WordPress Plugin Session Termination Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Masteriyo LMS WordPress plugin allows unauthenticated attackers to force any user, including administrators, to log out by exploiting an improperly authorized AJAX action. This could disrupt user access and site operations.

CVE advisoryCRITICAL

CVE-2026-12394

MemberGlut WordPress Plugin Role Permissions Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the MemberGlut WordPress plugin allows unauthenticated users to register with administrator privileges, potentially leading to full site compromise. This issue arises from a failure to validate user roles during front-end registration.