NVD disclosure day

Published threat advisories for August 1, 2026

CVE advisoryCRITICAL

CVE-2026-67342

ArcadeDB Authorization Bypass in HTTP Handlers Allows Unauthorized Database Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization bypass vulnerability in ArcadeDB's HTTP handlers allows unauthenticated attackers to access and modify databases by directly calling affected endpoints. This impacts handlers for time series, batch, Prometheus, and Grafana endpoints. The issue is relevant when these endpoints are reachable, potentially

CVE advisoryCRITICAL

CVE-2026-67341

ArcadeDB SQL DEFINE FUNCTION Authorization Bypass Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

ArcadeDB versions prior to 26.7.2 contain a critical vulnerability where scripting authorization checks for JavaScript functions are not enforced. Attackers with database access can exploit this by submitting `DEFINE FUNCTION` statements to execute arbitrary JavaScript code, bypassing intended security restrictions. Th

CVE advisoryCRITICAL

CVE-2026-67340

ArcadeDB Trigger Script OS Command Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in ArcadeDB's trigger script execution, allowing authenticated users with schema update permissions to achieve OS command execution. This occurs because the trigger script environment improperly allows lookups of certain Java classes, enabling the invocation of `java.lang.Runtime.getRunt

CVE advisoryCRITICAL

CVE-2026-67336

Better-Auth Insecure Cryptographic Defaults Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An issue in the better-auth library's OIDC and MCP plugins allows attackers to bypass security by using insecure cryptographic defaults, potentially accepting unsigned tokens or intercepting authorization codes. This could lead to unauthorized access if the library is used and exposed.

CVE advisoryCRITICAL

CVE-2026-67330

@better-auth SCIM Authorization Bypass Leads to Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization bypass in the @better-auth/scim plugin allows an authenticated user to mint a token that collides with an existing provider ID, enabling access to and control of other user accounts and sessions. This vulnerability can lead to account takeover, unauthorized data modification, and deprovisioning. The af

CVE advisoryCRITICAL

CVE-2026-67324

GitPython Clone Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

GitPython, a library for integrating Git operations into applications, has a vulnerability where it fails to properly validate certain command-line options. This could allow an attacker to trick an application using GitPython into executing arbitrary commands on the system during a repository clone. This matters if you

CVE advisoryCRITICAL

CVE-2026-67308

Wazuh GitHub Actions Shell Injection Via Crafted VERSION.json

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical shell injection vulnerability exists in Wazuh workflows, allowing attackers to execute arbitrary commands and exfiltrate secrets by submitting pull requests with crafted VERSION.json files. This affects GitHub Actions and could impact systems, particularly those with self-hosted runners, by enabling unauthor

CVE advisoryCRITICAL

CVE-2026-67305

FreeRDP Windows Client Heap Buffer Overflow Via Clipboard Channel

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap buffer overflow vulnerability exists in the FreeRDP Windows client when processing clipboard data. A malicious RDP server can cause memory corruption, potentially allowing remote code execution if a user pastes content. This issue is relevant to users connecting to untrusted RDP servers and performing paste oper

CVE advisoryCRITICAL

CVE-2026-67294

FreeRDP TLS Certificate EKU Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

FreeRDP improperly validates the Extended Key Usage of peer certificates during client-side server TLS authentication, potentially accepting client-only certificates as valid server certificates. This could allow a malicious server to impersonate a legitimate RDP server, undermining trust in remote connections. Organiz

CVE advisoryCRITICAL

CVE-2026-67293

FreeRDP Improper Certificate Validation Weakens TLS Authentication.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in FreeRDP weakens TLS server authentication by improperly validating wildcard certificates, potentially allowing malicious servers to masquerade as legitimate ones during connections. This could impact the trust of remote connections if exploited. Uncertainty remains regarding the specific client appli

CVE advisoryCRITICAL

CVE-2026-67292

FreeRDP WebSocket Buffer Over-Disclosure Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in FreeRDP's WebSocket transport could allow a malicious gateway to disclose client memory contents or cause a denial of service. The flaw involves how the client responds to specific network messages, potentially leaking sensitive data such as masking keys. Uncertainty remains regarding the specific us

CVE advisoryCRITICAL

CVE-2026-67289

FreeRDP HTTP Proxy Request Injection Via Redirection.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in FreeRDP may allow a malicious RDP server to inject arbitrary HTTP headers or requests into a client's connection through an HTTP proxy. This occurs when the RDP client does not properly validate control characters in redirection data, which can then be used to manipulate proxy `CONNECT` requests. Thi

CVE advisoryCRITICAL

CVE-2026-66402

FreeRDP TLS Certificate Validation Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Weaknesses in FreeRDP's TLS certificate validation can allow attackers to bypass server identity verification by presenting a specially crafted certificate. This could weaken TLS server authentication when FreeRDP is used, potentially allowing impersonation of legitimate servers.

CVE advisoryCRITICAL

CVE-2026-15964

WordPress Single Sign On Plugin Authentication Bypass Allows Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in the Single Sign On For TNG WordPress plugin enables unauthenticated attackers to bypass authentication and reset any user's password, potentially leading to complete website takeover. This vulnerability allows attackers to change passwords without proper verification, giving them control over the WordPress si

CVE advisoryCRITICAL

CVE-2026-3141

WordPress FormGent Plugin Arbitrary File Deletion Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The FormGent plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to delete arbitrary files, potentially leading to complete site takeover by deleting essential configuration files like `wp-config.php`. This issue stems from an improperly secured REST API endpoint within the plugin. The