NVD disclosure day

Published threat advisories for July 30, 2026

CVE advisoryCRITICAL

CVE-2026-38709

Cudy Routers Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in the `net.set_wan` interface of certain networking devices. Reachable via the internet, this flaw could permit unauthenticated attackers to execute arbitrary commands with root privileges on affected devices, potentially leading to a complete compromise. Confirming the presenc

CVE advisoryCRITICAL

CVE-2026-68502

LazyOwn Unauthenticated Remote Code Execution via Lazyc2.py

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the LazyOwn RedTeam/APT Framework allows unauthenticated remote code execution. If reachable, this could enable unauthorized command execution within the C2 process, posing a risk to system integrity. Confirmation of the framework's usage and exposure is advised.

CVE advisoryCRITICAL

CVE-2026-66803

Azure Cosmos DB Network Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Improper access control in Azure Cosmos DB, a cloud database service, allows unauthorized network access to execute code. This vulnerability could impact the confidentiality, integrity, and availability of the database. Confirming the use of this service and assessing potential exposure is a key concern.

CVE advisoryCRITICAL

CVE-2026-66418

OpenClaw Dashboard Stored XSS via Crafted Username in Failed Login

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenClaw Dashboard has a stored cross-site scripting vulnerability allowing unauthenticated remote attackers to inject HTML and script via a crafted username during a failed login attempt. If an administrator views the audit log, the injected code can execute in their session, potentially allowing unauthorized interact

CVE advisoryCRITICAL

CVE-2026-52539

Outstatic CMS Hardcoded Secret Allows Forged Admin Tokens.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hardcoded secret in Outstatic CMS allows unauthenticated attackers to forge session tokens and gain administrative access. This vulnerability could lead to unauthorized control over the content management system and access to user data. Confirming usage and exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-35847

Dnsmgr Ping Function Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in a DNS management tool's ping function allows a local attacker to execute arbitrary code. The issue could affect system data and service behavior if a local user can trigger the vulnerable function. Confirmation of the tool's presence and reachability within the environment is the initial concern.

CVE advisoryCRITICAL

CVE-2025-69947

SourceCodester Tailor Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SourceCodester Tailor Management System is affected by a critical SQL injection vulnerability in customeredit.php. This flaw allows unauthenticated attackers to potentially access, modify, or delete sensitive customer data. Organizations using this system should confirm its presence and assess potential impact.

CVE advisoryCRITICAL

CVE-2025-69941

SourceCodester Tailor Management System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a web-based tailor management system, potentially allowing attackers to execute malicious database commands over the network. This could lead to unauthorized access, modification, or deletion of sensitive data stored within the system. It is important to determine if this system

CVE advisoryCRITICAL

CVE-2025-69938

CodeAstro Membership Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the CodeAstro Membership Management System's renewal functionality, allowing unauthenticated attackers to potentially access, modify, or delete sensitive membership data. Organizations should identify any usage of this system and assess its reachability and criticality.

CVE advisoryCRITICAL

CVE-2025-69937

CodeAstro Membership Management SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the CodeAstro Membership Management System's `edit_type.php` endpoint. This flaw may permit unauthenticated attackers to execute arbitrary database commands, potentially leading to unauthorized access or modification of sensitive membership data if the system is external

CVE advisoryCRITICAL

CVE-2025-69936

CodeAstro Membership Management SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in a membership management system allows unauthenticated attackers to potentially access, alter, or delete sensitive data by manipulating web requests to the `/edit_member.php` script. This could compromise member data and system integrity, requiring confirmation of system usage and exposu

CVE advisoryCRITICAL

CVE-2025-69935

CodeAstro Membership Management SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the CodeAstro Membership Management System's reporting features, allowing unauthenticated attackers to manipulate database queries. This could lead to unauthorized access, modification, or deletion of sensitive membership data. The system's web interface is likely exposed to the

CVE advisoryCRITICAL

CVE-2025-69934

CodeAstro Membership Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the CodeAstro Membership Management System that could allow attackers to manipulate member data. If this system is reachable, unauthenticated actors could potentially read, modify, or delete sensitive information from the database. Confirming usage and external exposure

CVE advisoryCRITICAL

CVE-2025-69933

CodeAstro Membership Management System SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the CodeAstro Membership Management System, allowing unauthenticated network attackers to execute malicious SQL commands. This could lead to unauthorized access, modification, or deletion of sensitive membership data. The issue is in a web-accessible endpoint, suggesting potentia

CVE advisoryCRITICAL

CVE-2025-69930

CodeAstro Membership Management SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL Injection vulnerability exists in the CodeAstro Membership Management System's membership card printing function, potentially allowing unauthorized access and modification of sensitive data. The issue involves the `print_membership_card.php` script and requires network access for exploitation. This could

CVE advisoryCRITICAL

CVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in an e-commerce application's product price display script, potentially allowing attackers to access or modify sensitive database information. This issue is classified as external and critical, meaning it is reachable via the network. The vulnerability is in a file designed to show

CVE advisoryCRITICAL

CVE-2026-67594

Spikster API Authentication Bypass Allows Server Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Spikster where missing authentication allows unauthenticated remote attackers to access API routes. This could enable attackers to enumerate servers, reset passwords, access files, and create database users. Confirming relevance is key, as these API endpoints often manage sensitive fu

CVE advisoryCRITICAL

CVE-2026-67208

Juggle Unauthenticated Remote Code Execution via Exposed H2 Console

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Juggle contains a critical remote code execution vulnerability accessible via its H2 database web console using default credentials. This allows unauthenticated attackers to run arbitrary OS commands, potentially leading to root-level code execution. The technology is vulnerable if the H2 console is exposed and reachab

CVE advisoryCRITICAL

CVE-2026-12946

IBM Langflow OSS Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in IBM Langflow OSS, a tool for building AI workflows, where improper handling of user input could allow an unauthenticated remote attacker to inject and execute arbitrary code on the system. This could lead to system compromise, affecting data integrity and availability. It is important

CVE advisoryCRITICAL

CVE-2026-66066

Action Pack Unsafe Libvips Operation Allows Arbitrary File Read

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Action Pack framework allows a crafted upload to invoke unsafe libvips operations, potentially exposing sensitive files and credentials. This could enable remote code execution or lateral movement if the application uses libvips and accepts untrusted image uploads.

CVE advisoryUNKNOWN

CVE-2026-51272

ESP32-audioI2S Heap Buffer Overflow Enables Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability in the schreibfaul1 ESP32-audioI2S library's character encoding function could allow an attacker to execute code, disclose information, or cause a denial of service. This occurs if the library processes malicious, oversized input, leading to an out-of-bounds write. The actual

CVE advisoryCRITICAL

CVE-2026-48499

Activepieces Tenant File Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Activepieces, an open-source AI workflow automation platform, has a vulnerability where an authenticated flow author can access and modify cached files of other tenants on the same worker. This could lead to sensitive data exposure and the execution of malicious code on a victim tenant's next flow run.

CVE advisoryCRITICAL

CVE-2026-15976

SGLang Remote Code Execution via Pickle Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

SGLang contains a critical remote code execution vulnerability when loading model weights from HuggingFace repositories, enabling attackers to deserialize malicious code in .bin files. This could allow arbitrary code execution on the affected system if reachable. Confirming the exposure and relevance of deployed SGLang

CVE advisoryCRITICAL

CVE-2026-15971

SGLang RCE Vulnerability Allows Sandbox Escape

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in SGLang's optional dumper subsystem, when enabled and configured with a specific server port, may allow for sandbox escape and remote code execution through inference requests. This could permit an attacker to run unauthorized code on the affected system. The key concern is to determine if th

CVE advisoryCRITICAL

CVE-2026-15969

SGLang RCE via Incomplete SafeUnpickler Denylist

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SGLang, a framework for large language model serving, contains a critical vulnerability allowing unauthenticated command execution via crafted payloads that bypass an incomplete denylist. This flaw could compromise system integrity and data if the affected technology is reachable.

CVE advisoryCRITICAL

CVE-2026-13435

IBM Langflow PythonREPL Sandbox Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS contains an improper input validation vulnerability in its PythonREPL sandbox. If reachable and exploited, this could allow an attacker to execute arbitrary code, potentially leading to unauthorized access and manipulation. Organizations using this technology should confirm its presence and assess pote

CVE advisoryCRITICAL

CVE-2026-12943

IBM HMC Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Hardware Management Console software contains a vulnerability allowing unauthenticated users to execute arbitrary commands with elevated privileges due to improper input validation. This could impact system data and behavior if the console is network-reachable, affecting critical administrative interfaces for IBM P

CVE advisoryCRITICAL

CVE-2026-12118

IBM webMethods Integration Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in IBM webMethods Integration, allowing unauthenticated remote attackers to execute arbitrary code by deserializing untrusted data. This could compromise system integrity and confidentiality if the integration platform is reachable.

CVE advisoryUNKNOWN

CVE-2026-51291

SQLite JSON Cache Use After Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical use-after-free vulnerability exists in the JSON cache management module of SQLite. If reachable, this flaw could allow an attacker to corrupt, modify, or disclose data processed by applications using this library. Understanding the extent to which your systems utilize SQLite for JSON processing is essential

CVE advisoryUNKNOWN

CVE-2026-51290

SQLite Use-After-Free in Shared Cache Locking

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in SQLite's shared cache lock management, potentially leading to denial of service or sensitive memory disclosure. This flaw arises from improperly freeing memory while it's still in use within the btree module's linked list. Although SQLite is typically embedded and not directly e

CVE advisoryCRITICAL

CVE-2026-12940

IBM Langflow OSS Unauthenticated Remote Code Execution via Environment Variable Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS is vulnerable to unauthenticated remote code execution through environment variable injection in its MCP stdio launcher. An attacker could exploit this to run unauthorized commands on affected systems, potentially impacting operations and data integrity. It is important to confirm if this technology is

CVE advisoryCRITICAL

CVE-2026-52680

Apache Kyuubi Path Traversal Via REST Batch Upload.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache Kyuubi's REST batch upload handling contains a path traversal vulnerability. A remote attacker could exploit this to write controlled content to arbitrary filesystem locations, subject to server permissions. This could impact system integrity. Confirm if Kyuubi is in use and assess its exposure.

CVE advisoryCRITICAL

CVE-2026-4978

UMAI Vision Traffic Analysis System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the UMAI Vision Traffic Analysis System, potentially allowing attackers to execute unauthorized SQL commands. This could lead to data manipulation or system disruption. Uncertainty exists regarding specific affected versions and the extent of potential business impact.

CVE advisoryCRITICAL

CVE-2026-28812

Apache JSPWiki UserManager Impersonation Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Apache JSPWiki's UserManager allows for privilege escalation, potentially enabling attackers to impersonate users due to a lack of input validation. This could lead to unauthorized access and modification of sensitive wiki content. Organizations should identify all instances of the software,

CVE advisoryCRITICAL

CVE-2026-28323

SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SAML authentication bypass vulnerability affects SolarWinds Web Help Desk when SAML 2.0 is enabled. Reachable instances could allow unauthenticated attackers to bypass login controls, potentially leading to unauthorized system access. This warrants confirmation of product usage and exposure within your envir

CVE advisoryCRITICAL

CVE-2026-53431

Boruta JWT Authentication Bypass via Replay Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in the malach-it Boruta library allows attackers to replay expired JWT client assertions to impersonate OAuth clients and gain unauthorized access. This could enable access to client resources with the client's privileges. The issue is considered critical and affects systems using

CVE advisoryCRITICAL

CVE-2026-15435

IBM App Connect Enterprise Directory Traversal Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical directory traversal vulnerability in IBM App Connect Enterprise could allow remote attackers to write arbitrary files to the system via specially crafted URL requests. This affects system integrity and could lead to further compromise if the affected product is exposed externally. Confirmation of deployed in

CVE advisoryCRITICAL

CVE-2026-11707

IBM Tivoli System Automation Application Manager and WebSphere Application Server Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A cross-site scripting vulnerability exists in the administrative console login page of IBM Tivoli System Automation Application Manager and IBM WebSphere Application Server. This could allow an attacker to inject malicious scripts, potentially leading to unauthorized actions or information disclosure within a user's s

CVE advisoryCRITICAL

CVE-2026-59310

VMware vCenter Syslog Server Directory Traversal Vulnerability Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A directory traversal vulnerability exists in VMware vCenter's Syslog server, potentially allowing an unauthenticated attacker with network access to execute arbitrary code. The severity is high, but the actual risk depends on whether the Syslog service is exposed to untrusted networks.

CVE advisoryCRITICAL

CVE-2026-54363

CentreStack Hardcoded Key Enables Unauthenticated Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

CentreStack contains a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge encrypted tokens and access privileged API endpoints. This could enable domain administrator privileges and unauthenticated remote code execution. Confirmation of system relevance and exposure is advised due to

CVE advisoryCRITICAL

CVE-2026-18363

osTicket Password Reset Token Validation Logic Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A logic flaw in osTicket's password reset function allows attackers to bypass expiry checks if they obtain a valid reset token, potentially leading to unauthorized account takeovers. This vulnerability in the token validation routine means that tokens with existing timestamps might not be properly validated for expirat

CVE advisoryCRITICAL

CVE-2026-7849

Remote Command Injection Vulnerability in System Configuration Enables Root Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists where improper handling of special elements allows an unauthenticated remote attacker to inject commands into system configurations, which are then executed as root. This could lead to unauthorized system-level modifications and potential compromise. The issue is relevant if the affected

CVE advisoryCRITICAL

CVE-2026-44104

Charging Controller Firmware Compromise via Unverified Updates

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in charging controller basemodule firmware updates, where a lack of cryptographic signature verification allows unauthenticated remote attackers to install modified firmware, potentially leading to full system compromise. The main concern is confirming the relevance and exposure of this

CVE advisoryCRITICAL

CVE-2026-44090

MQTT Broker Missing Authentication Allows Full Device Compromise.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated remote attacker can access an MQTT broker due to missing authentication, potentially leading to full device compromise. Although protected by a firewall, a bypass could expose this critical vulnerability. Leaders should confirm if this technology is in use and assess its potential exposure and impact

CVE advisoryCRITICAL

CVE-2026-58046

Plesk XML-RPC API SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Plesk XML-RPC API allows authenticated users to inject SQL commands, potentially enabling them to read sensitive data from the Plesk database and achieve full control over the hosting panel. This issue is relevant for organizations using Plesk for web hosting management and requires attention to

CVE advisoryCRITICAL

CVE-2026-14602

Remote Code Execution in Remote API WordPress Plugin Via Unauthenticated Input Deserialization.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated deserialization vulnerability in the Remote API WordPress plugin allows attackers to inject malicious code, potentially leading to remote code execution if a suitable gadget chain is present. This could impact the integrity and availability of affected websites and their data.

CVE advisoryCRITICAL

CVE-2026-16610

Admin and Site Enhancements Pro Plugin Unauthenticated Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Admin and Site Enhancements Pro WordPress plugin has a critical vulnerability that allows unauthenticated attackers to execute code remotely. This is possible because a frontend save handler lacks authentication and validation, and input is processed without sanitization before being used in an eval() call. Exploit

CVE advisoryCRITICAL

CVE-2026-18015

Chromium Tint Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An inappropriate implementation in the Tint component of Google Chrome on Mac could allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This vulnerability requires user interaction with a malicious website, and while the Chromium security severity is low, it presents a potential risk of una

CVE advisoryCRITICAL

CVE-2026-18002

Google Lens Sandbox Escape in Chrome

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Lens within Chrome allows a sandbox escape via a crafted HTML page, potentially impacting the renderer process. This could grant attackers broader system access if they have already compromised the renderer process and a user interacts with a malicious page. While the Chromium security severit

CVE advisoryCRITICAL

CVE-2026-17990

Chrome WebAuthn Sandbox Escape via Crafted PDF

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's WebAuthn feature may allow a remote attacker who has already compromised the renderer process to escape the browser's sandbox by using a crafted PDF file. This issue is related to insufficient validation of untrusted input. While a prior compromise is necessary, successful exploitatio

CVE advisoryCRITICAL

CVE-2026-17947

Chrome Use After Free in WebSockets Allows Sandbox Escape.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Google Chrome's WebSockets, potentially allowing a remote attacker to escape the browser's sandbox by tricking a user into visiting a crafted HTML page. This could enable an attacker to execute code outside the browser's security boundaries. The relevance and exposure of this cl

CVE advisoryCRITICAL

CVE-2026-17940

Chrome for Android Picture-in-Picture Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Google Chrome on Android has a vulnerability in its Picture-in-Picture feature where insufficient input validation could allow a remote attacker, who has compromised the renderer process, to escape the browser sandbox via a crafted HTML page. This could potentially expose system data and alter service behavior, though

CVE advisoryCRITICAL

CVE-2026-17924

Chrome DNS Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the DNS component of Google Chrome, which could allow an attacker who has already compromised the renderer process to escape the browser's sandbox. This could potentially lead to unauthorized code execution on the affected system. The primary concern is to determine if this tech

CVE advisoryCRITICAL

CVE-2026-17865

Google Chrome Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's crypto implementation could allow a remote attacker to escape the browser sandbox via a crafted HTML page. This requires prior compromise of the renderer process and user interaction with a malicious site, potentially impacting system or user data accessible from within the sandbox.

CVE advisoryCRITICAL

CVE-2026-17856

Google Chrome Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome on Mac could allow a remote attacker to escape the browser's sandbox via a crafted HTML page, potentially leading to unauthorized system access. This requires a user to visit a malicious webpage to compromise the renderer process. It is uncertain if specific environments are exposed to

CVE advisoryCRITICAL

CVE-2026-17855

Google Chrome DevTools Race Condition Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in Google Chrome's DevTools on Mac may allow a compromised renderer process to escape the browser's sandbox. If reachable, this could lead to unauthorized access or modification of data. The relevance and exposure to our environment are currently being assessed.

CVE advisoryCRITICAL

CVE-2026-17848

Google Chrome Codecs Sandbox Escape Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Google Chrome's codecs could allow a remote attacker to escape the browser sandbox by tricking a user into opening a crafted video file. This could potentially lead to unauthorized system actions, though user interaction is required. The relevance to your environment depends on users opening such

CVE advisoryCRITICAL

CVE-2026-17834

Chrome Sandbox Escape Vulnerability in Password Management

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security vulnerability in Google Chrome's password handling could allow a compromised renderer process to escape the browser's sandbox via a crafted HTML page. This could potentially expose sensitive user data or allow for further system compromise if a user visits a malicious web page. The relevance and exposure of

CVE advisoryCRITICAL

CVE-2026-17832

ANGLE Use After Free in Chrome May Allow Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in ANGLE, a component of Google Chrome, could allow a remote attacker to escape the browser's sandbox by tricking a user into visiting a crafted HTML page. This could potentially impact system integrity and confidentiality. Uncertainty exists regarding specific Chrome versions affected and the lik

CVE advisoryCRITICAL

CVE-2026-17804

Google Chrome Use After Free Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's media handling could allow a remote attacker to escape the browser's sandbox, potentially impacting data integrity and confidentiality. This vulnerability is triggered when a user visits a crafted HTML page, and its relevance depends on the use of this technology and po

CVE advisoryCRITICAL

CVE-2026-17801

ANGLE Sandbox Escape via HTML Page in Chrome

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ANGLE, a component of Google Chrome, could allow a remote attacker to escape the browser's sandbox by using a crafted HTML page. This may lead to unauthorized access or control of the user's system. The risk to your environment depends on whether affected browser versions are reachable and process se

CVE advisoryCRITICAL

CVE-2026-17768

Chrome Sandbox Escape Vulnerability Via Malicious HTML

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's WebSockets could allow a remote attacker, after compromising the browser's renderer, to escape the sandbox via a malicious HTML page, potentially impacting user data and system integrity. The risk is considered very unlikely as it requires user interaction with a crafted webpage.

CVE advisoryCRITICAL

CVE-2026-17727

Google Chrome for Android WebGL Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome for Android's WebGL component could allow attackers to escape the browser sandbox by tricking users into visiting a malicious HTML page. This could potentially lead to unauthorized access or manipulation of data on affected devices if reached.

CVE advisoryCRITICAL

CVE-2026-17721

Google Chrome ANGLE Out-of-Bounds Write Vulnerability Allows Sandbox Escape

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in ANGLE, a Google Chrome component, could allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This requires user interaction, making it a lesser threat to infrastructure but still posing a risk if users access malicious content.

CVE advisoryCRITICAL

CVE-2026-17711

Google Chrome Sandbox Escape via Malicious HTML

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in Google Chrome on Macs allows a compromised renderer process to escape the browser's sandbox via a crafted HTML page. This could potentially impact system integrity and confidentiality. While direct reachability from the internet is considered unlikely, relevance should be confirmed.

CVE advisoryCRITICAL

CVE-2026-17701

ANGLE Sandbox Escape in Google Chrome on Mac

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in ANGLE for Google Chrome on Mac could allow a malicious website to escape the browser's security sandbox. This is due to insufficient validation of untrusted input, which could be triggered by a user visiting a compromised webpage, potentially leading to broader system compromise. The concern is to co

CVE advisoryCRITICAL

CVE-2026-17695

ANGLE Sandbox Escape in Google Chrome for Mac

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A sandbox escape vulnerability in ANGLE, used by Google Chrome on Mac, could allow a remote attacker to bypass security protections via a crafted HTML page, potentially impacting the confidentiality and integrity of data. The vulnerability is rated as high severity.

CVE advisoryCRITICAL

CVE-2026-17692

Chrome Sandbox Escape Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome could allow a remote attacker to escape the browser's sandbox. This may occur if a user visits a malicious HTML page, potentially enabling unauthorized access to systems. The relevance to our environment requires confirmation.

CVE advisoryCRITICAL

CVE-2026-17691

ANGLE Sandbox Escape Vulnerability in Google Chrome on Windows

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in ANGLE, a component within Google Chrome on Windows, could allow a remote attacker to escape the browser's sandbox via a crafted HTML page. This could potentially lead to unintended access or behavior within the system. The reader should care because this could result in broader system compromise.

CVE advisoryCRITICAL

CVE-2026-17688

Chrome Input Use After Free Vulnerability Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's input handling could allow a remote attacker, who has already compromised the renderer process, to escape the browser's sandbox via a crafted HTML page. This requires user interaction with a malicious website.

CVE advisoryCRITICAL

CVE-2026-17687

ANGLE Type Confusion Vulnerability in Chrome Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A type confusion vulnerability in ANGLE, used in Google Chrome, allows a remote attacker to escape the browser sandbox via a malicious HTML page. This could lead to broader system compromise if a user is tricked into visiting such a page. The main concern is confirming the relevance and exposure of this client-side vul

CVE advisoryCRITICAL

CVE-2026-17682

ANGLE Integer Overflow in Google Chrome Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in ANGLE within Google Chrome allows a compromised renderer process to potentially escape the sandbox via a crafted HTML page. This could lead to elevated privileges or system compromise. The vulnerability's client-side nature and requirement for prior compromise make its direct reachability uncerta

CVE advisoryCRITICAL

CVE-2026-17680

ChromeOS Color Heap Buffer Overflow Vulnerability Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap buffer overflow in Google Chrome on ChromeOS could allow a remote attacker who has already compromised the renderer process to escape the browser's sandbox via a crafted HTML page. This could lead to broader system access. The issue requires chained exploits and is classified as high severity within Chromium.

CVE advisoryCRITICAL

CVE-2026-17676

ANGLE Sandbox Escape Vulnerability in Chrome for Android

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in ANGLE within Google Chrome on Android may permit an attacker who has compromised the renderer process to escape the browser sandbox via a crafted HTML page, potentially leading to broader system access. This is relevant due to the severe impact of sandbox escapes, although the attacker must first ach

CVE advisoryCRITICAL

CVE-2026-17675

ANGLE Sandbox Escape via Crafted HTML

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome's ANGLE component could allow a remote attacker who has compromised the renderer process to escape the browser sandbox via a crafted HTML page. This could affect system confidentiality, integrity, and availability. Confirming relevance to our environment is the initial priority

CVE advisoryCRITICAL

CVE-2026-17673

Google Chrome QUIC Integer Overflow Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Google Chrome's QUIC implementation that could allow a compromised renderer process to escape its sandbox. An attacker could exploit this by tricking a user into visiting a malicious website. This may lead to unauthorized access to system data and service behavior.

CVE advisoryCRITICAL

CVE-2026-17671

ANGLE Sandbox Escape Vulnerability in Google Chrome

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A high-severity vulnerability in ANGLE, a component of Google Chrome, could allow a sandbox escape via a crafted HTML page if an attacker compromises the renderer process. This could potentially lead to elevated access and affect system or user data. The issue's reachability depends on users visiting malicious webpages

CVE advisoryCRITICAL

CVE-2026-17670

Google Chrome Use-After-Free Vulnerability Allows Sandbox Escape.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's rendering engine could allow a remote attacker to escape the browser's sandbox and potentially access system resources. This could occur if a user visits a malicious web page containing specially crafted code. The impact is not yet fully understood as exploitation detai

CVE advisoryCRITICAL

CVE-2026-17666

Google Chrome Cryptographic Flaw Allows Access Control Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A cryptographic flaw in Google Chrome enables an attacker in a privileged network position to bypass access controls via malicious network traffic, potentially impacting data integrity. The threat is classified as external due to its network vector, but its direct enterprise impact is unlikely given its client-side nat

CVE advisoryCRITICAL

CVE-2026-17655

ANGLE Sandbox Escape in Google Chrome

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's ANGLE component could allow a remote attacker to escape the browser sandbox via a malicious HTML page. This could potentially lead to broader system compromise. The reader should care to assess the relevance of this component in their environment.

CVE advisoryCRITICAL

CVE-2026-17652

Google Chrome Sandbox Escape via Use After Free in Views

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome's Views component may allow a remote attacker to escape the browser's security sandbox via a crafted HTML page, impacting system integrity and availability. This requires the attacker to first compromise the renderer process and trick a user into visiting a malicious webpage. T

CVE advisoryCRITICAL

CVE-2026-17651

Chrome for Android Dawn Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Google Chrome on Android, stemming from insufficient validation of untrusted input in the Dawn component. This flaw could allow a remote attacker to escape the browser's sandbox by tricking a user into visiting a malicious HTML page. The potential impact could include significant comp