NVD disclosure day

Published threat advisories for July 29, 2026

CVE advisoryCRITICAL

CVE-2026-67595

VaahCMS Malicious JavaScript in OTP Email Templates

Halo Surface Signal: 3 out of 5 — possibly public-facing.

VaahCMS contains malicious JavaScript in its security email templates, which could execute code in a user's browser and capture sensitive information if the emails are rendered with JavaScript enabled. The vulnerability allows remote attackers to establish unauthorized WebSocket connections, install keyloggers, and scr

CVE advisoryCRITICAL

CVE-2025-69943

Hospital Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a Hospital Management System, allowing unauthenticated attackers to manipulate database queries via specific parameters. This could lead to unauthorized access or modification of sensitive data if the system is reachable.

CVE advisoryCRITICAL

CVE-2025-69942

CVE-2025-69942 Kishan0725 Hospital Management System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in Kishan0725 Hospital Management System's patient viewing component. Unauthenticated attackers can exploit this via network requests to potentially access or alter sensitive patient data. This issue is classified as external and likely affects internet-facing systems, warranting a

CVE advisoryCRITICAL

CVE-2025-67404

Automated Enrollment System SQL Injection Vulnerability in save_stud.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Sourcecodester CASAP Automated Enrollment System is susceptible to SQL injection via parameters in `save_stud.php`, potentially allowing unauthorized data access or manipulation. The vulnerability's impact depends on whether the system is in use and exposed.

CVE advisoryCRITICAL

CVE-2025-67403

Sourcecodester CASAP Automated Enrollment System SQL Injection in update_class.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in the Sourcecodester CASAP Automated Enrollment System allows unauthenticated network access to manipulate the `class_name` parameter in `update_class.php`. This could lead to unauthorized data access or modification within the system's database, posing a significant risk if the

CVE advisoryCRITICAL

CVE-2025-65340

Hospital Management System SQL Injection Vulnerability in Reporting Module

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the kishan0725 Hospital Management System's reporting component, potentially allowing unauthorized access to sensitive data. If reachable, an attacker could manipulate database queries to read, modify, or delete information. This issue could impact data integrity and confidential

CVE advisoryCRITICAL

CVE-2026-67429

Flyto2 Core Arbitrary File Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Flyto2 Core's file writing modules do not sufficiently validate output paths, allowing the process to write arbitrary data to any accessible filesystem location. This vulnerability could lead to system compromise or data manipulation if reachable. Its relevance depends on how Flyto2 Core is implemented and exposed with

CVE advisoryCRITICAL

CVE-2026-67426

Flyto2 Core SSRF and Secret Exfiltration Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Flyto2 Core's verification service could allow unauthenticated attackers to perform server-side requests and exfiltrate runner secrets. This impacts the core kernel for automation and AI-agent workflows. Understanding Flyto2 Core's role in your environment is key to assessing potential exposure.

CVE advisoryCRITICAL

CVE-2026-16326

Consul-mcp-server Session State Isolation Bypass Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in `consul-mcp-server` allows a client's Consul authentication token to be used for subsequent requests from other clients when operating in stateless mode. This could lead to unauthorized access to session state and potentially sensitive information. Readers should care because this flaw could allow un

CVE advisoryCRITICAL

CVE-2026-14529

IBM WebSphere Application Server SSRF Vulnerability with SIP Container Enabled

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical server-side request forgery vulnerability exists in IBM WebSphere Application Server when the SIP container feature is enabled, allowing unauthenticated attackers to make the server issue unintended requests to arbitrary network locations. This could potentially expose internal network structures or sensitiv

CVE advisoryCRITICAL

CVE-2026-41939

Hard-coded Credentials in Care Everywhere Gateway Allow Remote Code Execution via WildFly

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hard-coded credentials vulnerability in the Care Everywhere Gateway's WildFly management interface allows unauthenticated attackers to gain administrative access and execute code. The affected technology is an outdated, end-of-life product, but misconfigurations can expose it. Confirm relevance to avoid potential com

CVE advisoryCRITICAL

CVE-2026-18236

Agent Development Kit Continuation Forgery Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Agent Development Kit (ADK) may allow an attacker to execute unauthorized tools by forging confirmation responses if session history can be manipulated. This occurs because the ADK does not adequately verify if a target tool is registered, requires confirmation, or if confirmation arguments match

CVE advisoryCRITICAL

CVE-2026-8338

Coverity Connect Authentication and Authorization Bypass.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication and authorization bypass vulnerability exists in Coverity Connect, enabling unauthenticated attackers to access sensitive data by sending specially crafted HTTP requests. This issue could allow unauthorized viewing of internal data within the static analysis results management platform. Readers should

CVE advisoryCRITICAL

CVE-2026-54680

Logging operator command injection vulnerability in fluent.conf rendering

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the logging operator that allows a user with Flow resource creation privileges to inject and execute arbitrary commands within the Fluentd aggregator. This could compromise the integrity and availability of logging data. Confirming relevance and exposure in your environment is important.

CVE advisoryCRITICAL

CVE-2026-51992

ClickHouse Server SQL Injection Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability in ClickHouse Server may allow a remote attacker to execute arbitrary code. This issue could affect system data and behavior if exploited. It is uncertain if ClickHouse is deployed or reachable within the environment.

CVE advisoryKnown Exploit

CVE-2026-20316

Cisco FMC Static Credentials Allow Low-Privilege Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Cisco Secure Firewall Management Center's web interface allows unauthenticated, remote attackers to use static credentials for a low-privileged account to access sensitive data. The risk is reduced if the management interface is not publicly accessible, but Cisco notes this can be combined with other

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-67192

Xlight FTP Server Pre-Authentication Stack Buffer Overflow via SSH GCM Cipher

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A pre-authentication stack buffer overflow in Xlight FTP Server allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated, potentially leading to remote code execution. This vulnerability is reachable over the network before any user authentication, posing

CVE advisoryCRITICAL

CVE-2026-67191

Xlight FTP Server Pre-Authentication Heap Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Xlight FTP Server has a critical pre-authentication heap buffer overflow vulnerability. Remote, unauthenticated attackers can exploit this by sending a malformed SSH client identification string, potentially leading to service disruption or other severe consequences on SSH or SFTP connections before authentication. Thi

CVE advisoryCRITICAL

CVE-2026-60113

AMMOS AIT DSN Missing Authentication in SLE API Routes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A missing authentication vulnerability exists in the AMMOS Instrument Toolkit's Deep Space Network interface, allowing unauthenticated attackers to access unprotected API routes. Attackers could potentially control communication sessions, retrieve telemetry, or inject arbitrary frames into spacecraft links. Confirmatio

CVE advisoryCRITICAL

CVE-2026-54735

Prebid Server SSRF Vulnerability Allows Internal Network Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Prebid Server, an open-source ad auction system, where improperly validated parameters can cause server-side requests to unintended destinations. This could expose internal network services or sensitive endpoints. Confirming relevance and public-facing exposure is essential for affect

CVE advisoryCRITICAL

CVE-2026-65888

Joomla Gridbox Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical account takeover vulnerability in a Joomla extension's social login feature allows unauthenticated actors to log in as any user. This could lead to unauthorized access to user accounts and their data on public-facing websites using the affected extension.

CVE advisoryCRITICAL

CVE-2026-65886

Joomla Gridbox Unauthenticated Arbitrary File Read

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated arbitrary file read vulnerability exists in the Gridbox Joomla extension's photo viewer. Attackers can exploit this to read any file on the server, potentially exposing sensitive information. Confirm if your organization uses this extension and assess your exposure.

CVE advisoryCRITICAL

CVE-2026-9177

Axway SecureTransport Admin SSTI Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Template Injection vulnerability in Axway SecureTransport allows an administrator to execute arbitrary Java code when an email is sent, potentially leading to full server compromise. This impacts users of the product, especially those with administrative access who may not be aware of the risk.

CVE advisoryCRITICAL

CVE-2026-65890

Joomla Gridbox Unauthenticated SQL Injection.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a Joomla extension, enabling unauthorized users to inject malicious SQL code into database queries, potentially leading to unauthorized data access or manipulation. The primary concern is confirming if this extension is in use and exposed online.The provided CVE

CVE advisoryCRITICAL

CVE-2026-65889

Balbooa Joomla Extension Unauthenticated Directory Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated actors to recursively delete directories, potentially leading to data loss and site disruption. Readers should care because this technology is often used in public-facing websites, making it a reachable threat. The primary concern is to confirm if th

CVE advisoryCRITICAL

CVE-2026-65885

Joomla Gridbox Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated arbitrary file upload vulnerability exists in the Gridbox Joomla extension, potentially enabling attackers to execute arbitrary code on the server if chained with another vulnerability. This issue affects systems running the affected Joomla extension.

CVE advisoryCRITICAL

CVE-2026-65884

Joomla Gridbox Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in a Joomla extension allows unauthenticated actors to escalate privileges by creating new administrative accounts. This could lead to unauthorized control over the affected website and its data. Confirming the use and reachability of this extension is crucial for assessing risk.

CVE advisoryCRITICAL

CVE-2026-0667

Modbus TCP Improper Exception Handling Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Modbus TCP protocol could allow an unauthenticated attacker to execute arbitrary code, disrupt services, or compromise data confidentiality and integrity. This issue is reachable via network communication over the Modbus TCP protocol, and its impact depends on the specific implementation and netw

CVE advisoryCRITICAL

CVE-2026-65883

Joomla Extension RCE via PHP Object Injection in Aimy Captcha-Less Form Guard

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated attackers to inject PHP objects, leading to remote code execution. This could enable attackers to compromise the web server hosting the extension by submitting a forged form field. Understanding if this extension is in use and externally reachable is

CVE advisoryCRITICAL

CVE-2026-14900

Cost Calculator Builder PRO WordPress Plugin Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a WordPress plugin allows unauthenticated attackers to execute arbitrary code on the server due to insufficient input sanitization before a PHP `eval()` function is called. The attacker can obtain necessary nonces from publicly available data, making the vulnerability easily exploitable on a

CVE advisoryCRITICAL

CVE-2026-14488

Meta Box AIO Unauthenticated Arbitrary Post Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Meta Box AIO WordPress plugin allows unauthenticated attackers to delete arbitrary posts and pages. The flaw is in the frontend submission feature, where deletion requests are not properly checked, enabling attackers to remove content without login or permissions if a submission form is

CVE advisoryCRITICAL

CVE-2026-59243

FAB Auth Manager Azure AD OAuth Signature Verification Bypass Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The FAB auth manager's Azure AD OAuth login can be bypassed by an attacker presenting a forged ID token, granting them access as any user, including administrators. This vulnerability impacts deployments using the default configuration, where signature verification is not enforced.

CVE advisoryCRITICAL

CVE-2026-58179

Apache Traffic Server Regex Remap Plugin Stack and Integer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Apache Traffic Server regex_remap plugin allows for stack and integer overflows from substitution input, potentially impacting server availability and integrity. This issue is relevant because Apache Traffic Server is an internet-facing gateway, and exploitation could lead to denial-of-service or

CVE advisoryCRITICAL

CVE-2025-10656

Spreadsheet Price Changer WooCommerce Plugin Vulnerable to Unauthorized Admin Account Creation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Spreadsheet Price Changer WordPress plugin allows unauthenticated attackers to create administrator accounts. This could lead to unauthorized control and potential compromise of affected websites. It is important to confirm the plugin's presence and relevance within your digital assets to assess

CVE advisoryCRITICAL

CVE-2026-58155

Apache Traffic Server Header Aliasing and Policy Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Apache Traffic Server has a vulnerability where it truncates overly long header names, potentially allowing header aliasing, request smuggling, and policy bypass. This issue affects the server's request processing, and if reachable, attackers could exploit it to circumvent security measures. Organizations using Apache

CVE advisoryCRITICAL

CVE-2026-18191

Vacron VIN-DS783E-E6 Hidden Functionality Credential Disclosure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hidden functionality vulnerability in Vacron VIN-DS783E-E6 devices allows unauthenticated remote attackers to obtain administrator credentials. This could lead to unauthorized device control. It is important to identify deployed devices and assess their reachability and business criticality.

CVE advisoryCRITICAL

CVE-2026-63234

Koollab LMS SQL Injection and Unsafe Deserialization Leading to Webshell and Arbitrary Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection and unsafe deserialization vulnerability in Koollab LMS allows an authenticated attacker to execute arbitrary code on the server by injecting data through the manual mark assessment endpoint. This could lead to unauthorized control of the system. If Koollab LMS is used and externally reachable, this iss

CVE advisoryCRITICAL

CVE-2026-63233

Koollab LMS SQL Injection and Unsafe Deserialization Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Koollab LMS permits authenticated attackers to execute arbitrary code via SQL injection and unsafe deserialization in the assessment answer endpoint, potentially leading to webshell creation and server compromise. Confirming Koollab LMS usage and its accessibility is essential.

CVE advisoryCRITICAL

CVE-2026-63232

Koollab LMS SQL Injection and Unsafe Deserialization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection and unsafe deserialization vulnerability in Koollab LMS could allow an authenticated attacker to execute arbitrary code on the server. This issue is reachable via the assessment reinforcement endpoint and could lead to system compromise. Readers should care because this vulnerability could enable unauth

CVE advisoryCRITICAL

CVE-2026-63230

Koollab LMS SQL Injection Allows Pre-Authentication Database Read and Account Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A pre-authentication SQL injection vulnerability in Koollab LMS allows unauthenticated attackers to read sensitive database contents, potentially leading to account takeover via stolen credentials and JWTs. This issue is relevant due to the LMS's typical web-facing nature and the exposure of the SCORM report endpoint.

CVE advisoryCRITICAL

CVE-2026-63227

Koollab LMS Unrestricted SCORM Upload Vulnerability Allows Arbitrary Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unrestricted SCORM file upload vulnerability in Koollab LMS allows an authenticated user to upload a PHP webshell, potentially leading to arbitrary code execution on the server. This could impact system integrity and data confidentiality, necessitating an assessment of organizational use of the affected technology.

CVE advisoryCRITICAL

CVE-2026-13423

Streamit WordPress Theme Arbitrary Function Invocation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Streamit WordPress theme allows unauthenticated attackers to call arbitrary PHP functions, potentially leading to privilege escalation and remote code execution. This could enable attackers to create administrator accounts or execute malicious code on the server. Confirmation of the theme's prese

CVE advisoryCRITICAL

CVE-2026-18072

WordPress Advanced Responsive Video Embedder Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a WordPress video embedder plugin, allowing unauthenticated attackers to bypass authentication and gain administrative control of a site. The flaw stems from a hardcoded backdoor that provides universal administrator credentials. This could lead to full site compromise and data manipu