NVD disclosure day

Published threat advisories for August 2, 2026

CVE advisoryKnown Exploit

CVE-2026-18577

N-central Authentication Bypass Enables Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incomplete security patch for N-central allows for authentication bypass and account takeover, granting attackers administrative access. This could lead to compromised systems, data breaches, and unauthorized control over managed devices. Organizations should prioritize applying the vendor's hotfix to affected N-cen

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-65321

PyAthena SQL Injection via Improper Quote Escaping

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A SQL injection vulnerability exists in PyAthena due to improper quote escaping, enabling unauthenticated attackers to inject arbitrary SQL. This could lead to unauthorized data exfiltration, modification, or the creation of malicious tables. The impact depends on how PyAthena is integrated into affected systems.

CVE advisoryCRITICAL

CVE-2026-68582

Vikunja Task-Collection Endpoint Broken Object Level Authorization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Vikunja's task-collection endpoint has a broken object-level authorization flaw. Attackers with a project share link can view unauthorized bucket titles and user information from other tenants' projects and views. This vulnerability could expose sensitive data and reveal project/view existence.

CVE advisoryCRITICAL

CVE-2025-71401

better-auth npm denial of service via base path poisoning

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the better-auth npm package allows an attacker to poison the router's base path, leading to a denial of service where all routes return 404. This can occur if the `baseURL` is not explicitly configured and an attacker makes the first request after server startup. While no data is explicitly at risk,

CVE advisoryCRITICAL

CVE-2026-16256

POUCO WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the POUCO Import Users WordPress plugin, allowing unauthenticated attackers to create administrator accounts and potentially take over websites by exploiting improperly checked user-submitted data. Readers should care because this flaw could grant attackers full control of a website w

CVE advisoryCRITICAL

CVE-2026-8457

WooCommerce Social Login Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The WooCommerce - Social Login plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, including administrators, by supplying a forged token. This occurs because the plugin does not properly verify token signatures or validate critical claims, and a security nonce