NVD disclosure day

Published threat advisories for August 5, 2026

CVE advisoryCRITICAL

CVE-2026-71319

Nuxt DevTools Remote Code Execution via Unauthenticated RPC Channel

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Nuxt DevTools, a development tool for Vue.js applications, that could allow an unauthenticated attacker to execute arbitrary code on a developer's machine. This is possible because an unauthenticated RPC channel within the DevTools lacks proper security checks. This risk is limited to developm

CVE advisoryCRITICAL

CVE-2026-48168

PraisonAI Claude GitHub Actions Workflow Command Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability exists in the PraisonAI Claude GitHub Actions workflow. Attackers can exploit this by using specially crafted branch names in pull requests to execute arbitrary shell code, potentially compromising the GitHub runner and repository. This affects code integrity and access controls within

CVE advisoryCRITICAL

CVE-2026-70426

Jenkins Remoting JEP-200 Deserialization Filter Bypass

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Jenkins Remoting's deserialization implementation, allowing bypass of the JEP-200 class filter through a fallback path. This could permit agent processes, code on agents, or attackers with specific permissions to execute unauthorized code. This is relevant if your environment uses affected Jen

CVE advisoryCRITICAL

CVE-2026-20310

Cisco Catalyst SD-WAN Improper Link Resolution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco Catalyst SD-WAN software has vulnerabilities related to improper link resolution before file access. If reachable, this could allow unauthorized modification or access to system data. Leadership should confirm the relevance and exposure within their environment.

CVE advisoryCRITICAL

CVE-2026-20304

Cisco Catalyst SD-WAN Improper Access Control Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Improper access control vulnerabilities in Cisco Catalyst SD-WAN software could allow an attacker to gain unauthorized access to sensitive functions or data. The specific impact is uncertain, but such flaws are critical for network infrastructure security. Determining reachability and criticality is essential.

CVE advisoryCRITICAL

CVE-2026-20303

Cisco Catalyst SD-WAN Improper Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cisco Catalyst SD-WAN software has vulnerabilities due to improper input validation. An attacker could exploit this to gain unauthorized access, potentially disrupting services or affecting system data. Confirming if this technology is used in your environment is the primary concern.

CVE advisoryCRITICAL

CVE-2026-20272

Cisco IOS XE Improper Neutralization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

This advisory concerns a critical vulnerability in Cisco IOS XE Software related to improper neutralization of special elements (CWE-74). If reachable, an unauthenticated remote attacker could exploit this issue, potentially leading to arbitrary code execution and a compromise of the device. Cisco has released software

CVE advisoryCRITICAL

CVE-2026-20267

Cisco IOS XE Software Improper Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Improper access control flaws in Cisco IOS XE Software could permit an unauthenticated, remote attacker to gain unauthorized access. Cisco IOS XE is critical network infrastructure, making potential vulnerabilities a concern for unauthorized system access or service disruption.

CVE advisoryCRITICAL

CVE-2026-9195

Progress MarkLogic Query Console Cross-Site Scripting Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A cross-site scripting vulnerability in Progress MarkLogic Server's Query Console allows remote attackers to execute arbitrary JavaScript in an administrator's browser session if they are lured to a crafted URL. This could lead to credential theft and unauthorized privileged actions. The relevance of this vulnerability

CVE advisoryCRITICAL

CVE-2026-9193

Progress MarkLogic Hadoop Integration Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper privilege management vulnerability in Progress MarkLogic Server's Hadoop integration allows authenticated users with low-privileged Hadoop roles to escalate privileges and execute privileged operations against the Security database. This could occur if the Hadoop integration is enabled and relevant in your

CVE advisoryCRITICAL

CVE-2026-9192

Progress MarkLogic Server ODBC Authentication Bypass Leads to Privileged Query Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication bypass in MarkLogic Server's ODBC App Server allows unauthenticated remote attackers to execute queries as any user, including administrators. This vulnerability is concerning if the ODBC App Server is exposed externally.

CVE advisoryCRITICAL

CVE-2026-9190

MarkLogic Server HTTP Request Smuggling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Progress MarkLogic Server's HTTP App Server may allow unauthenticated attackers to bypass security, hijack sessions, or steal credentials by exploiting how the server interprets HTTP requests. This could lead to unauthorized access and compromise of sensitive information.

CVE advisoryCRITICAL

CVE-2026-8709

MarkLogic Server REST API Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper privilege management vulnerability in Progress MarkLogic Server's REST API could allow an authenticated, low-privileged user to escalate their privileges and perform privileged operations on the Security database. This is a critical issue that affects systems managing sensitive data and potentially critical

CVE advisoryCRITICAL

CVE-2026-7557

Progress MarkLogic Server SAML Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper cryptographic signature verification in Progress MarkLogic Server's SAML module allows unauthenticated attackers to impersonate users, including administrators, when SAML single sign-on is enabled. This could lead to unauthorized access to system data and user information.

CVE advisoryCRITICAL

CVE-2026-7329

Progress MarkLogic Privilege Escalation via REST Query Interfaces.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper privilege management vulnerability in Progress MarkLogic Server's REST query interfaces allows an authenticated, low-privileged user to escalate privileges to administrator. This could enable unauthorized data access and the execution of privileged operations.

CVE advisoryCRITICAL

CVE-2026-39923

Flarum Password Reset Token Expiry Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flarum contains a vulnerability allowing unauthenticated attackers to reuse expired password reset tokens, potentially granting them access to any user account. This occurs because the reset processing endpoint does not validate token expiry. Readers should care because this could lead to unauthorized authenticated ses

CVE advisoryCRITICAL

CVE-2026-15587

Google SecOps Chronicle SOAR Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An improper privilege management vulnerability exists in Google SecOps (Chronicle SOAR) that, if exploited by an authenticated attacker using a crafted internal header, could lead to system-level administrative access. This could impact system data and service behavior. The vulnerability has been patched.

CVE advisoryCRITICAL

CVE-2026-71289

NASA ANMS and DTNMA REST API Unauthenticated Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the NASA-AMMOS Asynchronous Network Management System's reference implementation allows unauthenticated network access to its management service. This bypasses security controls, enabling attackers to send unauthorized commands to managed agents and manipulate data. Readers should care because this c

CVE advisoryCRITICAL

CVE-2026-71278

Unauthenticated Arbitrary JavaScript Execution in rust-iot-platform Calc Rule API.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can achieve arbitrary JavaScript execution in the rust-iot-platform server process by creating and triggering a malicious calc rule. The vulnerability exists in an API endpoint that is reachable without authentication and executes user-supplied scripts without sandboxing. This could allow an

CVE advisoryCRITICAL

CVE-2026-71277

Rust IoT Platform Auth Token Validation Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the rust-iot-platform's API allows unauthorized access by accepting any value in the Authorization header, bypassing authentication checks for protected endpoints. This means any request with a non-empty header could grant access to sensitive operations or data. The platform's security integrity is c

CVE advisoryCRITICAL

CVE-2026-71268

OpenPLC Runtime Arbitrary File Write via Crafted Structured Text Programs Enabling Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in OpenPLC Runtime allows arbitrary file writes to the filesystem when processing specially crafted Structured Text files, potentially enabling remote code execution. The issue stems from unvalidated file paths within uploaded program files, and the presence of hardcoded default credentials lowers the b

CVE advisoryCRITICAL

CVE-2026-71267

Microtar Stack Buffer Overflow Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the microtar library's header functions, where processing filenames longer than 99 characters can cause a stack buffer overflow. This could potentially lead to code execution or application crashes if an application using the library processes externally supplied, oversized filenames.

CVE advisoryCRITICAL

CVE-2026-71263

FreeModbus LINUXTCP Out-of-Bounds Write

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in FreeModbus's LINUXTCP port concerning an off-by-one bounds check, potentially allowing an unauthenticated attacker to cause a buffer overflow via a crafted Modbus TCP packet. While typically used in isolated industrial networks, if this software is reachable, it could affect system integrity a

CVE advisoryCRITICAL

CVE-2026-71262

IoTSharp BlobStorage Unauthenticated Path Traversal Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in IoTSharp's Blob Storage Controller, allowing unauthenticated remote attackers to access and manipulate arbitrary files. This path traversal flaw enables unauthorized writing, reading, modification, or deletion of files, potentially leading to remote code execution through the upload o

CVE advisoryCRITICAL

CVE-2026-71256

nanoMODBUS Out-of-Bounds Read Leads to Arbitrary Write

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in nanoMODBUS allows an attacker to write to arbitrary memory locations via a malicious Modbus response. This could lead to system compromise if the Modbus server is reachable over a network. Confirming the presence and exposure of this library in your environment is important.

CVE advisoryCRITICAL

CVE-2026-71254

nanoMODBUS Out-of-Bounds Write Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the nanoMODBUS library allows an unauthenticated attacker to write data outside a designated buffer by sending a crafted network request. This could result in denial of service or remote code execution. Security leaders should confirm if this technology is present in their operational technology envi

CVE advisoryCRITICAL

CVE-2026-71248

Inventory Management System PHP SQL Injection and Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

This critical vulnerability affects an Inventory Management System built with PHP, allowing unauthenticated attackers to bypass login or delete arbitrary product data through SQL injection. An attacker could gain unauthorized access to sensitive information or cause data loss by exploiting flaws in the system's handlin

CVE advisoryCRITICAL

CVE-2026-71238

DjangoCRM Hardcoded Secret Key and Debug Mode Lead to Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

DjangoCRM contains hardcoded security keys and leaves debug mode enabled by default. This allows unauthenticated attackers to forge session and password reset tokens, leading to account takeover and potential exposure of sensitive data such as database credentials. The issue arises from publicly accessible source code.

CVE advisoryCRITICAL

CVE-2026-71237

Miantang/IoT-PHP SQL Injection Vulnerability Affects Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the IoT-PHP login functionality, allowing unauthenticated attackers to bypass authentication and extract arbitrary data by exploiting unsanitized password input. The login route is reachable via the network, increasing the risk of exploitation.

CVE advisoryCRITICAL

CVE-2026-71231

IOTSmartHome Login SQL Injection Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IOTSmartHome's login functionality is vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication and extract arbitrary data, including user credentials. This occurs because the `checkCookie()` function improperly handles a decoded cookie, leading to a critical security flaw. Readers should

CVE advisoryCRITICAL

CVE-2026-66747

ZBTlink Router ENDLESSDOORS Implant grants unauthenticated root access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Zbtlink router firmware contains a hidden remote-control implant that grants unauthenticated root access. This implant phones home over cleartext TCP, allowing any party that can intercept or control this communication to execute arbitrary commands as root. The primary concern is confirming the relevance and exposure o

CVE advisoryCRITICAL

CVE-2026-44945

Rancher Privilege Escalation via Impersonation Middleware

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability exists in Rancher's impersonation middleware, allowing an authenticated user with the default global role to obtain full administrative access to the Rancher control plane and all managed clusters. This could lead to unauthorized administrative actions within the Rancher environment

CVE advisoryCRITICAL

CVE-2026-10090

Red Hat Advanced Cluster Management Subscription Controller Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Red Hat Advanced Cluster Management for Kubernetes' Application Subscription controller allows a user with edit privileges to escalate to full cluster-admin control. This is achieved by creating a subscription pointing to a malicious Helm repository, enabling the controller to apply cluster-scoped re

CVE advisoryCRITICAL

CVE-2026-10059

Multicluster Engine for Kubernetes ClusterCurator Privilege Escalation via ServiceAccount Token Minting

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the Multicluster Engine for Kubernetes ClusterCurator controller could allow a tenant administrator with namespace privileges to escalate to cluster-wide administrative authority. This is achieved by creating a specific resource, which inadvertently allows for the minting of a ServiceAccount token with full c

CVE advisoryCRITICAL

CVE-2026-71214

Aerie PlanDev Authorization Bypass Leading to Arbitrary Rule Insertion

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Aerie/PlanDev's authorization middleware permits unauthenticated attackers to insert arbitrary expansion rules and write command dictionaries. This could affect spacecraft command generation. The specialized nature of the technology makes its reachability and relevance uncertain.

CVE advisoryCRITICAL

CVE-2026-71213

Typemill Login Endpoint Rate-Limiting Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in Typemill's login endpoint that allows unauthenticated attackers to perform unlimited password-guessing attempts when CAPTCHA is disabled, which is the default configuration. This could lead to unauthorized access to user accounts, including administrator accounts. Readers should confirm if the

CVE advisoryCRITICAL

CVE-2026-71207

Stock-Inventory-Management-System SQL Injection Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Stock-Inventory-Management-System's login script contains a critical vulnerability allowing unauthenticated remote attackers to bypass authentication. This is achievable through SQL injection or by using hardcoded administrative credentials, potentially leading to unauthorized access and control of the inventory ma

CVE advisoryCRITICAL

CVE-2026-70376

Pluck CMS CSRF Vulnerability Allows Stored XSS and RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Pluck CMS's admin panel where it improperly validates request origins, potentially allowing attackers to trick authenticated administrators into performing unauthorized actions. By manipulating HTTP headers, an attacker could cause forged requests to be accepted, leading to the creation of mal

CVE advisoryCRITICAL

CVE-2026-61486

Apache Lucy Stack-Based Buffer Overflow Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stack-based buffer overflow vulnerability exists in the unsupported Apache Lucy search engine library, potentially allowing for unauthorized access and impact to data confidentiality, integrity, and availability. As the project is retired, there are no planned fixes, making it crucial to identify any usage and restri

CVE advisoryCRITICAL

CVE-2026-61484

Apache Lucy Deserialization of Untrusted Data Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A deserialization vulnerability exists in the unsupported Apache Lucy search engine library, potentially allowing remote code execution. Since the project is retired, no fix is available, and organizations should identify and restrict access to or replace any instances of this library.

CVE advisoryCRITICAL

CVE-2026-5581

Multi Uploader for Gravity Forms WordPress Plugin Unauthorized Media Deletion Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Multi Uploader for Gravity Forms WordPress plugin allows unauthenticated attackers to delete any media attachment. This could potentially lead to the destruction of the entire media library, impacting the availability of website content. The issue is reachable via public-facing forms.

CVE advisoryCRITICAL

CVE-2026-4431

Easy Post Submission Unauthorized Post Modification Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Easy Post Submission plugin for WordPress has a vulnerability that allows unauthenticated attackers to modify post titles, content, and categories, or unpublish posts by setting their status to draft. This is due to a missing capability check in the `create_post()` function when handling the `rbsm_submit_post` AJAX

CVE advisoryCRITICAL

CVE-2026-49004

PostgreSQL Command Injection Allows Root Access on Mobile Devices

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in a PostgreSQL service on mobile devices, allowing local attackers to bypass security and gain root access by exploiting misconfigurations and command injection flaws. This service runs with elevated privileges and weak credentials, making it a target for unauthorized system control.

CVE advisoryCRITICAL

CVE-2026-15360

Ajax Load More WordPress Plugin SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the Ajax Load More WordPress plugin that allows unauthenticated attackers to perform SQL injection, potentially extracting sensitive database data. This issue is relevant because it can be exploited remotely and affects public-facing websites.

CVE advisoryCRITICAL

CVE-2026-9273

WordPress Kadence Memberships Password Reset Poisoning Leads to Account Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The WordPress Kadence Memberships plugin has a vulnerability allowing unauthenticated attackers to poison password reset links, leading to account takeover by tricking users into clicking a malicious link that leaks reset information to the attacker. This could compromise user and administrator accounts.