NVD disclosure day

Published threat advisories for July 31, 2026

CVE advisoryCRITICAL

CVE-2026-68771

ComfyUI LoadTrainingDataset Unsafe Deserialization RCE

Halo Surface Signal: 3 out of 5 — possibly public-facing.

ComfyUI's LoadTrainingDataset node has an unsafe deserialization flaw. Unauthenticated remote attackers can exploit this by uploading a crafted pickle file, leading to arbitrary Python code execution. This could compromise the ComfyUI process. Assess if ComfyUI is deployed and reachable in your environment.

CVE advisoryCRITICAL

CVE-2026-68770

Sentence-Transformers Local Model Load Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The sentence-transformers library has a critical vulnerability where attackers can achieve arbitrary code execution by manipulating local model files, bypassing security settings intended to prevent this. This flaw allows malicious code to run during the model loading process when an application uses the library with r

CVE advisoryCRITICAL

CVE-2026-54725

Vault Secrets Webhook Service Account Token Leakage Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vault-secrets-webhook, a Kubernetes component for secret injection, has a vulnerability that could allow a low-privileged attacker to send ServiceAccount JWTs to an attacker-controlled Vault address. This occurs when the webhook is misconfigured with malicious annotations, potentially leading to sensitive informati

CVE advisoryCRITICAL

CVE-2026-67822

Tenda W6-S Stack Overflow in WiFi SSID Endpoint.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack-based buffer overflow exists in Tenda W6-S networking devices, allowing unauthenticated attackers to overwrite memory via network requests. This could lead to denial of service or compromise device integrity and confidentiality if the affected endpoint is reachable.

CVE advisoryCRITICAL

CVE-2026-58048

cPanel SQL Mode Preservation Vulnerability Allows Root Context Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in cPanel, a web hosting control panel, allows an attacker with low privileges to execute arbitrary SQL commands with root-level access by exploiting improper preservation of SQL mode during database renaming. This could lead to system compromise, impacting data and service behavior. The reader should c

CVE advisoryCRITICAL

CVE-2026-52855

Wings Configuration Data Disclosure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Wings server control plane allows low-privileged users to read sensitive configuration details, including authentication tokens, when specific placeholders are present in egg configuration files. This could potentially lead to further compromise of the game server management panel. Organizations

CVE advisoryCRITICAL

CVE-2026-17566

pgAdmin 4 Import/Export Data Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in pgAdmin 4's Import/Export Data tool allows an authenticated user to execute arbitrary commands. This occurs due to improper validation of user-supplied SQL queries, which can be exploited to inject malicious commands executed by the PostgreSQL client. The issue requires the `tools_import_export_data`

CVE advisoryCRITICAL

CVE-2026-17351

pgAdmin 4 SQL Injection via AI Assistant Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in pgAdmin 4 could allow attackers to bypass security measures, potentially enabling unintended SQL execution or remote code execution. This issue reintroduces a prior risk by allowing specially crafted commands to be executed if an attacker can trick the AI Assistant into processing them. The primary c

CVE advisoryCRITICAL

CVE-2026-17349

pgAdmin 4 Improper Credential Handling Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in pgAdmin that allows a user to clone another user's shared server, inheriting their stored database credentials. This could grant unauthorized access to sensitive data and database privileges. You should care if your environment uses pgAdmin for managing PostgreSQL databases.

CVE advisoryCRITICAL

CVE-2026-17561

Logsign SIEM Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical code injection vulnerability exists in Logsign SIEM, potentially allowing attackers to execute arbitrary code remotely without authentication. This could compromise the SIEM's integrity and availability, impacting the data it processes. The primary concern is determining if this technology is present and rea

CVE advisoryCRITICAL

CVE-2025-67649

PHP Jabbers Car Rental Script SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection flaw in a car rental script allows unauthenticated attackers to inject malicious SQL code through sorting functions, potentially leading to unauthorized data access or modification. Confirmation of its use within the organization is advised.

CVE advisoryCRITICAL

CVE-2026-18452

DMS+ Use of Hard-coded Credentials Allows Unauthenticated Device Control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

DMS+ (Non-Mobile) has a critical vulnerability where hard-coded credentials allow unauthenticated remote attackers to gain control over all installed devices by exploiting a fixed API key. This could lead to a complete loss of device security for all DMS+ installations if they are network-accessible.

CVE advisoryCRITICAL

CVE-2026-14483

Realtyna Organic IDX and WPL Real Estate WordPress Plugins Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Realtyna Organic IDX and WPL Real Estate WordPress plugins contain an arbitrary file upload vulnerability due to insufficient file type validation and hardcoded API credentials. This allows unauthenticated attackers to upload and execute malicious files, potentially leading to remote code execution.

CVE advisoryCRITICAL

CVE-2026-63223

CodeIgniter Upload Validation Vulnerability Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in CodeIgniter's file upload validation could allow remote attackers to upload and execute code by bypassing filename extensions. This impacts applications using specific validation rules that store uploaded files in web-accessible directories where scripts can run. The primary concern is understanding

CVE advisoryCRITICAL

CVE-2026-63221

CodeIgniter Query Builder SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in CodeIgniter's Query Builder deleteBatch() function allows user-controlled values to be interpreted as SQL, potentially leading to unauthorized data modification or deletion. This affects versions 4.3.0 through 4.7.3. Confirming if this specific function is used in deployed applications is crucial.

CVE advisoryHIGH

CVE-2026-43831

Unauthenticated Log Message Overflow Allows Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in log message functionality that could allow an unauthenticated attacker to execute code. Exploitation requires specific conditions and may impact system integrity. Uncertainty remains regarding the specific reachability of this function in typical deployments.

CVE advisoryCRITICAL

CVE-2026-43830

CVE-2026-43830 Network Vulnerability with High Impact

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical network vulnerability has been identified, potentially allowing unauthenticated attackers to gain high levels of control over affected systems, impacting confidentiality, integrity, and availability. Full details on the specific technology and precise impact are currently restricted and will be published lat