NVD disclosure day

Published threat advisories for August 4, 2026

CVE advisoryCRITICAL

CVE-2026-45537

OpenSIPS URI Construction Buffer Overflow in construct_uri() Function

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpenSIPS, a SIP server, contains a buffer overflow vulnerability in its `construct_uri()` function. Attackers can exploit this by sending crafted requests to overwrite memory, potentially altering server routing behavior and disrupting services. This issue affects servers that are externally reachable.

CVE advisoryCRITICAL

CVE-2026-45100

OpenSIPS Buffer Overflow in s.b64encode String Transformation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpenSIPS servers have a buffer overflow vulnerability in the `s.b64encode` transformation that could allow a remote attacker to corrupt message processing data. This issue arises when a routing script applies this transformation to oversized, attacker-controlled input within a SIP message, potentially impacting service

CVE advisoryCRITICAL

CVE-2026-70554

MaxSite CMS Unauthenticated PHP Object Injection in maxsite_comuser Cookie

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MaxSite CMS has a critical vulnerability allowing unauthenticated code execution via a crafted `maxsite_comuser` cookie. This occurs because the system improperly deserializes user-supplied data, potentially enabling remote code execution and property-oriented programming attacks if gadget chains are available. This is

CVE advisoryCRITICAL

CVE-2026-67979

NASA cFS Executive Services Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An access control flaw in NASA cFS Executive Services may permit attackers to execute arbitrary code by placing a shared object on target storage. This vulnerability could impact the integrity and confidentiality of system data. The technology is specialized for spacecraft systems, and its reachability or relevance wou

CVE advisoryCRITICAL

CVE-2026-66902

Perl Google Auth Command Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Google::Auth library for Perl could allow an attacker to execute arbitrary commands if an application uses external account credentials with a specified executable. This happens because the library runs commands from configuration files without sufficient gating, potentially impacting system inte

CVE advisoryCRITICAL

CVE-2026-45538

OpenSIPS SIP Server Stack Buffer Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in OpenSIPS, a SIP server, allows for a stack buffer overflow when processing excessively long header names in SIP messages, potentially leading to a denial of service or remote code execution. This issue is reachable via unauthenticated network packets to the SIP port if the server's routing script inv

CVE advisoryCRITICAL

CVE-2026-70553

MaxSite CMS Unauthenticated Remote Code Execution via Install Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject and execute arbitrary PHP code by sending crafted POST requests to the install endpoint. This injection manipulates configuration files, leading to persistent code execution as the web server process. Attackers can exploit t

CVE advisoryCRITICAL

CVE-2026-70552

MaxSite CMS AJAX Dispatcher Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in MaxSite CMS that allows unauthenticated attackers to access administrative endpoints. This could enable unauthorized manipulation of sensitive data like poll states and vote counts within the content management system. It is important for organizations using this CMS to

CVE advisoryCRITICAL

CVE-2026-70478

Flowise OAuth2 Credential Refresh Unauthorized Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flowise has an unauthenticated API endpoint that allows an attacker to access stored credentials for connected services. This could lead to unauthorized access to those services and exhaustion of refresh token quotas. This issue is relevant if Flowise instances are network-accessible.

CVE advisoryCRITICAL

CVE-2026-70477

Flowise CSV Agent Prompt Injection Executes Arbitrary Code

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A prompt injection vulnerability in Flowise's CSV Agent node could allow an attacker to execute arbitrary Python code within the service's environment. This occurs when a malicious prompt causes the LLM to generate a script that bypasses validation. You should care if you use Flowise and its chatflows are reachable, as

CVE advisoryCRITICAL

CVE-2026-69703

Atlas-Livre Admin Controllers Bypass Session Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Atlas-Livre contains an improper access control vulnerability that allows unauthenticated attackers to bypass session authentication. By sending raw HTTP requests to admin controllers, attackers can invoke destructive administrative actions like record deletion because the system fails to exit after redirects.

CVE advisoryCRITICAL

CVE-2026-49435

Keysight IxChariot Stack Buffer Overflow Allows Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Keysight IxChariot Endpoint products are vulnerable to a stack-based buffer overflow, allowing unauthenticated remote attackers to execute arbitrary code with administrative privileges by sending a specially crafted packet. This could impact system integrity and administrative control.

CVE advisoryCRITICAL

CVE-2026-0163

VPU Use After Free Allows Remote Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in video processing functions, which could allow an attacker to escalate privileges remotely without user interaction. While the vulnerability is rated critical, its reachability is considered unlikely due to its local nature.

CVE advisoryCRITICAL

CVE-2017-20242

Keysight IxChariot Endpoint Stack Overflow Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Keysight IxChariot Endpoint software contains a stack-based buffer overflow vulnerability. An unauthenticated remote attacker can exploit this by sending a specially crafted packet to crash the endpoint or potentially execute arbitrary code. Its relevance and exposure to operations need to be confirmed.

CVE advisoryCRITICAL

CVE-2017-20241

Keysight IxChariot Endpoint Heap Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow vulnerability exists in Keysight IxChariot Endpoint software, allowing unauthenticated remote attackers to crash the endpoint or potentially execute arbitrary code by sending crafted packets. The actual risk depends on the deployment context and network accessibility of the affected systems

CVE advisoryCRITICAL

CVE-2026-70470

Flowise Python Code Validation Bypass Allows OS Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Flowise, a tool for building LLM flows, allows bypassing code validation via Unicode characters to achieve arbitrary Python and OS command execution on the host. This impacts systems where Flowise is used to build and run AI workflows.

CVE advisoryCRITICAL

CVE-2026-69264

Flowise CSVAgent RCE via CSV Data URI Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flowise CSVAgent is vulnerable to remote code execution when processing specific CSV data. An attacker can craft malicious input to execute arbitrary commands on the server, potentially compromising the system. This is a critical issue because it allows for unauthorized server control and access to data.

CVE advisoryCRITICAL

CVE-2026-24254

NVIDIA Dynamo Multimodal Serving Out-of-Bounds Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

NVIDIA Dynamo for Linux has a critical vulnerability in its multimodal serving topology that could allow an unauthenticated attacker to cause an out-of-bounds write. This could lead to code execution, privilege escalation, data tampering, denial of service, or information disclosure.

CVE advisoryCRITICAL

CVE-2026-69259

Flowise SQLite Record Manager Database Path Overwrite Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Flowise's SQLite Record Manager allows an authenticated attacker to overwrite the database path, potentially leading to arbitrary code execution. This could impact system configuration files and allow for shell command injection when the application launches Chromium.

CVE advisoryCRITICAL

CVE-2026-69256

Flowise CSVAgent Python Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flowise versions prior to 3.1.3 contain a critical vulnerability in the CSVAgent node that allows an authenticated user to execute arbitrary Python code by supplying a malicious payload. This could lead to unauthorized command execution on the server when a chatflow is triggered.

CVE advisoryCRITICAL

CVE-2026-69255

Flowise CSVAgent Python Injection Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flowise, a tool for building large language model flows, has a vulnerability where specially crafted CSV data can be used to inject and execute arbitrary Python code. This code can lead to the execution of operating system commands with root privileges within the Flowise container.

CVE advisoryCRITICAL

CVE-2026-64633

Remote Unauthenticated Code Execution on Agent Host

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability permits remote, unauthenticated code execution on agent hosts. This means an attacker could potentially compromise an agent and any systems it can access. The primary concern is confirming the reachability and relevance of this issue within our environment.

CVE advisoryCRITICAL

CVE-2026-63456

HPE Networking SD-WAN Orchestrator REST API Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Multiple vulnerabilities in HPE Networking SD-WAN Orchestrator's REST API allow unauthenticated remote attackers to bypass web authentication and access system functions. This could lead to the viewing and modification of sensitive information, impacting network management and data integrity.

CVE advisoryCRITICAL

CVE-2026-63455

HPE Networking SD-WAN Orchestrator REST API Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Multiple vulnerabilities in HPE Networking SD-WAN Orchestrator's REST API permit unauthenticated attackers to bypass web authentication and access system functions. This could enable an attacker to view and modify sensitive system information. The REST API interface is typically reachable for administrative functions,

CVE advisoryCRITICAL

CVE-2026-58073

Veeam Service Provider Console Credential Impersonation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Veeam Service Provider Console allows an unauthenticated attacker to impersonate a managed agent, potentially obtaining its credentials. This could lead to unauthorized access to agent resources if the console is reachable.

CVE advisoryCRITICAL

CVE-2026-58072

Veeam Service Provider Console Arbitrary File Write Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Veeam Service Provider Console permits arbitrary file writes on the management server, potentially leading to remote code execution. This issue is significant because it could allow attackers with partial administrative access to compromise the management server by writing malicious files to

CVE advisoryCRITICAL

CVE-2025-29296

H3C Network Devices Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Multiple command injection vulnerabilities in several H3C network devices allow remote attackers to execute arbitrary commands as root. This could lead to complete device compromise if an attacker crafts malicious requests to specific API interfaces, exploiting improperly validated user input. The vulnerability is exte

CVE advisoryCRITICAL

CVE-2026-69254

Flowise Authenticated Command Injection via Custom Function Import

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker in Flowise, a tool for building LLM flows, can exploit a vulnerability in JavaScript execution to run arbitrary system commands as root. This occurs when a custom function imports a component that bypasses security settings, allowing the import of any built-in module, including `child_process`

CVE advisoryCRITICAL

CVE-2026-69253

Flowise Code Injection via Malicious Base URL

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability exists in Flowise, affecting custom-tool components that run code in a sandbox. An authenticated user can exploit this by crafting a malicious `baseURL` to inject and execute arbitrary JavaScript code on the Flowise server, potentially impacting system data.

CVE advisoryCRITICAL

CVE-2026-69110

OpenCode Studio Unauthenticated File Read and Delete Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenCode Studio has a missing authentication vulnerability allowing unauthenticated attackers to read arbitrary files and delete video content through specific API endpoints. This could expose intermediate job artifacts and sensitive user data. Regular review of API security and timely patching are recommended.

CVE advisoryCRITICAL

CVE-2026-69098

Kotaemon Insecure Deserialization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An insecure deserialization vulnerability in kotaemon allows unauthenticated attackers to execute arbitrary code by sending crafted input to the `check_connection` endpoint. This could lead to unauthorized access and control over the application's environment. The main concern is confirming relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-18801

OpenMeter SQL Injection in Customer Usage Attribution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenMeter has a stored SQL injection vulnerability in how it handles customer usage attribution data. An attacker who can modify customer records could insert malicious values that, when queried, may execute unintended SQL commands, potentially impacting data integrity or confidentiality. The full business impact and s

CVE advisoryCRITICAL

CVE-2026-69251

Flowise Record Manager and Agent Memory Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Flowise allows authenticated users to execute arbitrary code on the server by manipulating configuration settings to load malicious JavaScript files. This could impact server operations and data. Understanding the reachability and criticality of Flowise deployments is important for assessing risk.

CVE advisoryCRITICAL

CVE-2026-61515

Puwell IP Camera Unauthenticated Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Puwell IP camera firmware contains an unauthenticated command injection vulnerability. Attackers can remotely send a crafted JSON payload to the DebugShell interface, allowing arbitrary operating system command execution, potentially leading to full device compromise. This is a concern for any internet-facing IP camera

CVE advisoryCRITICAL

CVE-2026-61514

Puwell IP Camera Authentication Bypass via TCP Port 23456

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Puwell IP camera firmware has an authentication bypass vulnerability that lets unauthenticated attackers access device functions and sensitive data. This flaw allows unauthorized control over live video, camera movement, and audio features through network-accessible functions. Determining if these devices are in use an

CVE advisoryCRITICAL

CVE-2026-60007

Eclipse Milo Padding Oracle Vulnerability Allows Password Recovery

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Eclipse Milo, an OPC UA implementation, allows an on-path attacker to recover user passwords and authenticate as a victim by exploiting distinguishable error messages during username-token processing. This could lead to unauthorized access, with the impact dependent on network reachability and the sp

CVE advisoryCRITICAL

CVE-2026-15721

HUMANIST Digital Human Resources Cleartext Storage and SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in HUMANIST Digital Human Resources due to cleartext storage of sensitive information, allowing potential remote exploitation. This could lead to unauthorized access and manipulation of data.

CVE advisoryCRITICAL

CVE-2026-14804

HUMANIST Digital Human Resources Hard-coded Key Disclosure Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in HUMANIST Digital Human Resources allows attackers to read sensitive constants from the executable due to a hard-coded cryptographic key. This could expose internal configuration details when the application is reachable over a network.

CVE advisoryCRITICAL

CVE-2026-14175

HUMANIST Digital Human Resources Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unrestricted file upload vulnerability in HUMANIST Digital Human Resources allows uploading a web shell to the web server. This could enable an unauthenticated attacker to compromise the server's integrity and confidentiality if the application is network-accessible. Confirming the presence and exposure of this soft

CVE advisoryCRITICAL

CVE-2026-18754

Lighttpd Firmware Static RSA Private Key Exposure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in product firmware due to an embedded, static RSA private key for the Lighttpd web server. This allows attackers to decrypt sensitive HTTPS communications and impersonate the device. It is uncertain if this technology is in use.

CVE advisoryCRITICAL

CVE-2026-18753

Lighttpd Firmware Static RSA Key Exposure Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in product firmware exposes a static RSA private key used by the Lighttpd web server for TLS termination. This exposure could allow malicious actors to decrypt HTTPS communications and impersonate the server, impacting data confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-16618

Improve SEO WordPress Plugin Unauthenticated Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A WordPress plugin vulnerability allows unauthenticated users to upload and execute PHP files, potentially leading to remote code execution. This occurs due to improper file upload validation where the plugin uses an attacker-supplied extension for saving files in a public directory.

CVE advisoryCRITICAL

CVE-2026-15958

Easy Integration for Dropbox WordPress Plugin File Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Easy Integration for Dropbox WordPress plugin has a critical vulnerability allowing unauthenticated attackers to list, download, and upload arbitrary files from a connected Dropbox account, and to read account and administrator email addresses. This issue could expose sensitive files and information.