NVD disclosure day

Published threat advisories for August 3, 2026

CVE advisoryCRITICAL

CVE-2026-48333

Adobe Campaign Classic Incorrect Authorization Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability exists in Adobe Campaign Classic, potentially allowing an attacker to escalate privileges without user interaction. This could lead to unauthorized elevated access on the platform. Attackers can reach the affected technology via the network.

CVE advisoryCRITICAL

CVE-2026-48330

Adobe Campaign Classic SQL Injection Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic has an SQL Injection vulnerability that may allow an unauthenticated attacker to execute arbitrary SQL commands, potentially leading to elevated access or control of the application without requiring user interaction. Confirming its use and external exposure is necessary for risk assessment.

CVE advisoryCRITICAL

CVE-2026-48326

Adobe Campaign Classic SQL Injection Vulnerability Allows Arbitrary Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Adobe Campaign Classic is affected by SQL injection, enabling a low-privileged attacker to execute arbitrary code in the user's context. This vulnerability, which does not require user interaction, could lead to a compromise of system operations and data integrity if reachable. The scope of the vulnerability is changed

CVE advisoryCRITICAL

CVE-2026-48323

Adobe Campaign Classic Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is vulnerable to arbitrary code execution due to improper handling of template engine elements. An unauthenticated attacker could exploit this by sending crafted data, leading to code execution within the user's context, impacting system confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-48317

Adobe Campaign Classic Eval Injection Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Improper Neutralization of Directives in Dynamically Evaluated Code vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code remotely, impacting data confidentiality and integrity. This issue could be exploited without user interaction when reachable.

CVE advisoryCRITICAL

CVE-2026-18667

Tenable Sensor Proxy Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Tenable Sensor Proxy allows remote attackers to execute code with elevated privileges. This occurs if an operator connects the sensor to an attacker-controlled host. Confirming the presence and potential exposure of this technology in your environment is important.

CVE advisoryCRITICAL

CVE-2026-46713

Misskey JSON-LD Signature Validation Vulnerability Allows Spoofed Activities

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Misskey's JSON-LD signature validation allows spoofed activities to be accepted as valid, potentially undermining platform integrity. This issue affects the core functionality of the federated social media platform, raising concerns about the acceptance of unauthorized or falsified user actions.

CVE advisoryCRITICAL

CVE-2026-69240

Sequelize Oracle SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Sequelize, a Node.js ORM, has a SQL injection vulnerability when using the Oracle dialect and specific string inputs are processed. An attacker could inject arbitrary SQL expressions if an application value reaches a vulnerable escape path, potentially impacting database queries.

CVE advisoryCRITICAL

CVE-2026-67598

Emlog Pro TLS Validation Bypass for API Key Interception

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Emlog Pro improperly validates TLS certificates for outbound requests to AI services, allowing network-adjacent attackers to intercept API keys and inject malicious AI responses. This could lead to unauthorized actions if the vulnerable communication channel is reachable.

CVE advisoryCRITICAL

CVE-2026-41452

Krayin CRM Installer Account Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing authentication vulnerability in Krayin CRM's installer middleware allows unauthenticated remote attackers to gain full administrative access by overwriting the primary administrator account via a crafted HTTP POST request, potentially exposing all CRM data. The vulnerability is reachable over the network and

CVE advisoryCRITICAL

CVE-2026-39932

OpenEMR Remote Code Execution via Document Category Tree

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenEMR systems contain a vulnerability in the document category tree component that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database. This could lead to command execution as the web server user, potentially impacting various pages

CVE advisoryCRITICAL

CVE-2026-18248

@fastify/aws-lambda Authentication Bypass via Header Injection CVE-2026-18248

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The @fastify/aws-lambda package, in version 6.4.0, allows unauthenticated attackers to bypass authentication and authorization by sending a crafted HTTP header to forge Lambda proxy event data. This could grant unauthorized access to applications that use this package for security decisions. The vulnerability is fixed

CVE advisoryCRITICAL

CVE-2026-9487

XML::Sig Signature Wrapping Vulnerability Allows SAML Assertion Tampering.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in XML::Sig allows signature wrapping through duplicate IDs, potentially enabling an attacker to manipulate SAML assertions by crafting XML documents that appear valid but contain attacker-controlled data. This could impact systems relying on XML signature verification for authentication and data integr

CVE advisoryCRITICAL

CVE-2026-9390

XML::Sig Library Vulnerable to XPath Injection.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the XML::Sig Perl library, allowing XPath injection through manipulated URI values during XML document verification. This could enable attackers to alter which data is processed for signature validation, potentially impacting data integrity and authenticity. The direct impact depends

CVE advisoryCRITICAL

CVE-2026-69085

SiYuan SQL Injection Allows Database Read and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

SiYuan's search API has a SQL injection vulnerability that allows attackers to read and modify data in cleartext notebooks. This is possible through the `/api/filetree/searchDocs` endpoint when publish mode is enabled or with a RoleReader token, as the keyword parameter is directly incorporated into SQL queries. The is

CVE advisoryCRITICAL

CVE-2026-69084

SiYuan SQL Injection via Search Embed Block Endpoint.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in SiYuan software, allowing unauthenticated attackers to read and modify data in cleartext notebooks via a SQL injection flaw in an API endpoint. This issue arises because the endpoint passes client-supplied SQL commands directly to the database without adequate restrictions, potentiall

CVE advisoryCRITICAL

CVE-2026-69083

SiYuan SQL Injection via FullTextSearchassetcontent Endpoint Affects Unauthenticated Users.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in SiYuan's fullTextSearchAssetContent endpoint, allowing unauthenticated users to execute arbitrary SQL commands. This could lead to the unauthorized reading, modification, or deletion of cross-notebook data by attackers who can reach the vulnerable endpoint. Organizations using Si

CVE advisoryCRITICAL

CVE-2026-68587

SiYuan Information Disclosure Vulnerability in Heading Endpoints.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan note-taking software contains an information disclosure vulnerability in its heading transaction endpoints that bypasses publish-access checks. Attackers can exploit this by supplying a heading block ID to read full rendered content of unpublished or restricted documents. This could expose sensitive information,

CVE advisoryCRITICAL

CVE-2026-68586

SiYuan Content Endpoints Leak Publish Forbidden Documents

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan versions before 3.7.3 improperly handle access controls for content retrieval endpoints, allowing unauthenticated users to access rendered content of publish-forbidden documents. This may expose sensitive information about document references, particularly in environments where publish-mode authentication is dis

CVE advisoryCRITICAL

CVE-2026-68584

SiYuan Authentication Bypass in Publish Mode Allows Full Content Retrieval.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in SiYuan's publish mode allows unauthenticated attackers to retrieve full content of password-protected documents by bypassing password checks. This could expose sensitive information that should otherwise be secured.

CVE advisoryCRITICAL

CVE-2026-64827

Telenia TVox Authentication Bypass in set_env.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass vulnerability exists in Telenia Software TVox within the set_env.php file. Attackers can exploit this by appending a specific string to a URL to bypass authentication and gain unauthenticated access to administrative PHP scripts, potentially leading to unauthorized access and control.

CVE advisoryCRITICAL

CVE-2026-18108

Net::SAML2 Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in Net::SAML2 for Perl that allows authentication bypass. If an affected service is configured to accept encrypted assertions, an unauthenticated party can craft a specially signed assertion, bypass verification checks, and impersonate any user. This impacts public-facing authentication services

CVE advisoryCRITICAL

CVE-2026-2346

Menulux Mobile App Authorization Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical authorization bypass vulnerability exists in the Menulux Software Inc. Mobile App, allowing software integrity attacks if reachable. This could lead to unauthorized access and manipulation of application functions. The potential business impact is uncertain, but this flaw warrants attention to understand its

CVE advisoryCRITICAL

CVE-2026-18574

Check Point Management Server Authentication Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management Servers may allow an unauthenticated remote attacker to execute arbitrary commands, potentially leading to a full compromise of the security management system. This issue could be relevant if management servic

CVE advisoryCRITICAL

CVE-2026-33591

Wapt Server Session Token Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Wapt Server that permits remote, unauthenticated attackers to bypass security restrictions and obtain valid session tokens for targeted accounts. This could potentially allow unauthorized access to the server and its managed systems. The relevance of this issue depends on the network exposure

CVE advisoryCRITICAL

CVE-2026-18588

Wavlink WL-NU516U1 fgets Stack Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack-based buffer overflow vulnerability exists in the `nas.cgi` component of Wavlink networking devices. This flaw can be exploited remotely by manipulating the `CONTENT_LENGTH` argument, potentially allowing attackers to execute arbitrary code. The vendor has released a fixed version, emphasizing the need to asses

CVE advisoryCRITICAL

CVE-2026-16534

WordPress Plugin User Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin that imports and exports users and customers has a vulnerability allowing users with minimal privileges to create administrator accounts or alter existing administrator credentials. This could enable unauthorized access to sensitive data and full control of a website.

CVE advisoryCRITICAL

CVE-2026-16532

Link Library WordPress Plugin SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Link Library WordPress plugin could allow unauthenticated users to perform SQL injection attacks. This means attackers could potentially access or alter sensitive data within the plugin's database. It is important to determine if this plugin is in use to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-16300

ChamaWP WordPress Plugin Password Reset Vulnerability Allows Site Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the ChamaWP WordPress plugin allows unauthenticated attackers to reset arbitrary user passwords, potentially leading to full website takeover. The flaw in the password reset process means that an attacker could gain administrative access if the plugin is in use and its reset functionality is

CVE advisoryCRITICAL

CVE-2026-16250

Personal QR Message WordPress Plugin Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WordPress plugin allows unauthenticated users to upload and execute arbitrary PHP files. This could lead to remote code execution on affected servers. The issue is externally reachable, posing a critical risk to public-facing WordPress sites.

CVE advisoryCRITICAL

CVE-2026-15930

Simple Membership WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Simple Membership WordPress plugin allows unauthenticated attackers to overwrite administrator account data and take over accounts. This occurs when user creation fails during registration, and the plugin incorrectly uses the returned value to update an account, enabling unauthorized control via

CVE advisoryCRITICAL

CVE-2026-12965

Super Store Finder WordPress Plugin SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Super Store Finder WordPress plugin, allowing unauthenticated attackers to extract database data. This issue stems from a failure to sanitize a parameter within an AJAX action, making it possible to inject malicious SQL queries. Any public-facing website using this p

CVE advisoryCRITICAL

CVE-2026-12872

Webinfos WordPress Plugin Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in the Webinfos WordPress plugin that allows unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory. This could enable remote code execution on affected servers if PHP files are executed from the uploads path, potentially compromising website integrity a

CVE advisoryCRITICAL

CVE-2026-8763

Bouncy Castle Name Constraints Bypass Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the Bouncy Castle Java cryptographic library that allows for bypassing name constraints. This could enable attackers to present fraudulent digital certificates, potentially leading to security policy violations or impersonation attacks. Its relevance depends on whether your environment utilize

CVE advisoryCRITICAL

CVE-2026-59650

Bouncy Castle Java Diffie-Hellman Exponentiation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in the Bouncy Castle Java cryptography library that could allow unvalidated peer values to be exponentiated during Diffie-Hellman key agreement. This may impact systems using the library for secure communications. Identifying its use and assessing potential risk is important.

CVE advisoryCRITICAL

CVE-2026-59638

Bouncy Castle Java Hostname Verification Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Bouncy Castle for Java, a cryptographic library, where a default setting can bypass security checks for secure connections. This could potentially lead to a loss of data integrity or confidentiality. The reachability and relevance of this issue within your environment need to be confi