NVD disclosure day

Published threat advisories for August 2, 2026

CVE advisoryCRITICAL

CVE-2026-65321

PyAthena SQL Injection via Improper Quote Escaping

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A SQL injection vulnerability exists in PyAthena due to improper quote escaping, enabling unauthenticated attackers to inject arbitrary SQL. This could lead to unauthorized data exfiltration, modification, or the creation of malicious tables. The impact depends on how PyAthena is integrated into affected systems.

CVE advisoryCRITICAL

CVE-2026-68582

Vikunja Task-Collection Endpoint Broken Object Level Authorization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Vikunja's task-collection endpoint has a broken object-level authorization flaw. Attackers with a project share link can view unauthorized bucket titles and user information from other tenants' projects and views. This vulnerability could expose sensitive data and reveal project/view existence.

CVE advisoryCRITICAL

CVE-2025-71401

better-auth npm denial of service via base path poisoning

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the better-auth npm package allows an attacker to poison the router's base path, leading to a denial of service where all routes return 404. This can occur if the `baseURL` is not explicitly configured and an attacker makes the first request after server startup. While no data is explicitly at risk,

CVE advisoryCRITICAL

CVE-2026-8457

WooCommerce Social Login Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The WooCommerce - Social Login plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, including administrators, by supplying a forged token. This occurs because the plugin does not properly verify token signatures or validate critical claims, and a security nonce