NVD disclosure day

Published threat advisories for August 6, 2026

CVE advisoryCRITICAL

CVE-2026-70558

Dinky Local File Write via Unvalidated Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dinky allows unauthenticated attackers to write arbitrary files by exploiting a path traversal flaw in a download handler, potentially leading to code execution. Reachable over the network, this issue impacts Dinky's integrity and availability by allowing overwrites of application files.

CVE advisoryCRITICAL

CVE-2026-67689

FineAdmin SQL Injection Vulnerability Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in FineAdmin V1.0 allows remote attackers to execute arbitrary code by manipulating parameters in paginated list endpoints. If reachable, this could impact system integrity and data confidentiality, warranting an assessment of your environment's relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-67688

ICS-Park Smart Park Management System Unrestricted File Upload Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the ICS-Park Smart Park Management System, allowing remote attackers to upload arbitrary files, which could lead to arbitrary code execution. This impacts the system's integrity and availability. Uncertainty exists regarding product versions, exploitation details, and specific busines

CVE advisoryCRITICAL

CVE-2026-5857

Contiki-NG MQTT Over-Length Topic Arbitrary-Pointer-Write

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Contiki-NG's MQTT client allows an attacker to perform an arbitrary-pointer write by sending an over-length topic, potentially leading to information disclosure, denial of service, or remote code execution on embedded devices. This occurs due to improper handling of topic lengths during message proce

CVE advisoryCRITICAL

CVE-2026-53983

Ground Station SSRF via Unauthenticated Socket.IO Configuration Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated server-side request forgery vulnerability exists in a ground station system, allowing attackers to compel the system to make outbound HTTP requests to attacker-chosen destinations. This can reveal internal network information or cloud metadata through the system's responses. The vulnerability persist

CVE advisoryCRITICAL

CVE-2026-48088

OpenReception Appointment Booking E2E Encryption Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability in OpenReception's appointment booking software allows attackers to insert their encryption keys, breaking end-to-end encryption and potentially exposing patient appointment data. The affected API endpoint improperly stores attacker-controlled public keys without proper authentication,

CVE advisoryCRITICAL

CVE-2026-48087

OpenReception Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpenReception's appointment booking software has a critical vulnerability in its registration handler. An unauthenticated attacker can exploit this flaw to take over user accounts by associating their own credentials with a victim's account, potentially leading to unauthorized access. Further assessment is needed to de

CVE advisoryCRITICAL

CVE-2026-48086

OpenReception Privilege Escalation via Tenant Admin Role Update.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in OpenReception's appointment booking software allows a tenant administrator to gain full administrative control over the entire platform and all other tenants' data. This privilege escalation could expose sensitive information and configurations if exploited. Addressing this issue is important to main

CVE advisoryCRITICAL

CVE-2026-48085

OpenReception Unauthenticated Admin Account Creation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenReception's appointment booking software is vulnerable to unauthenticated network attackers who can create new administrator accounts. This grants full platform control, potentially allowing unauthorized access and manipulation of appointment data. Confirming if this software is in use and exposed is advised.

CVE advisoryCRITICAL

CVE-2026-43632

llama.cpp Tokenization Use-After-Free Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in llama.cpp's server component affects tokenization endpoints, allowing attackers to exploit a race condition that could lead to crashes or code execution. This issue arises from improper memory management when handling specific HTTP requests on worker threads.

CVE advisoryCRITICAL

CVE-2026-43631

llama.cpp Use-After-Free via Sleep Idle Threads

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in llama.cpp's llama-server, when the `--sleep-idle-seconds` feature is enabled, could allow unauthenticated remote attackers to execute arbitrary code. This occurs during the server's sleep transition if concurrent worker threads access freed memory, which can then be reclaimed with atta

CVE advisoryCRITICAL

CVE-2026-43629

llama.cpp Heap Buffer Overflow in KV Cache Restore Leads to Memory Corruption

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap buffer overflow vulnerability in llama.cpp's KV cache restore path allows attackers with write access to the `slot_save_path` directory to corrupt heap memory. This could lead to model weight corruption or arbitrary code execution.

CVE advisoryCRITICAL

CVE-2026-3418

WSO2 System REST API Unrestricted File Upload Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a System REST API that allows authenticated administrators to upload files to arbitrary server locations, potentially leading to remote code execution. This issue requires administrative access and could impact system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-19166

Google Chrome Web Authentication Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in Google Chrome's Web Authentication feature could permit an attacker to escape the browser's sandbox through a malicious webpage. This could potentially compromise user data and system resources if a user visits such a page. It is uncertain if this vulnerability is reachable or relevant to your

CVE advisoryCRITICAL

CVE-2026-19164

Chrome Sandbox Escape Vulnerability in Codecs

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Google Chrome has a vulnerability in its codec handling that could allow a remote attacker to escape the browser sandbox if a user visits a crafted HTML page. This could potentially impact user systems. Further information is needed to determine if specific Chrome usage within the organization is exposed and at risk.

CVE advisoryCRITICAL

CVE-2026-19157

ANGLE Out-of-Bounds Write in Chrome for Android Enables Sandbox Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An out-of-bounds write vulnerability in the ANGLE component of Google Chrome on Android could permit a remote attacker to escape the browser's sandbox via a crafted HTML page. This could lead to unauthorized access to system resources or sensitive information.

CVE advisoryCRITICAL

CVE-2026-19149

Google Chrome Sandbox Escape Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical use-after-free vulnerability in Google Chrome on Linux could permit a remote attacker to escape the browser's sandbox through a crafted HTML page. This could potentially allow unauthorized system access. The threat is considered external as the attack vector is network-based.

CVE advisoryCRITICAL

CVE-2026-17032

Supsystic Pro Plugin Supply Chain Compromise Exfiltrates Data and Grants Site Control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Malicious code distributed through a compromised Supsystic Pro plugin update server allows unauthenticated attackers to steal sensitive data and gain full control of affected websites. This issue is relevant to internet-facing web applications accessible from the public internet.

CVE advisoryCRITICAL

CVE-2026-15734

WGDashboard SSTI Vulnerability Allows Root Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Template Injection vulnerability in WGDashboard allows authenticated attackers to execute arbitrary code as root. This could impact system data and potentially sensitive information. Confirmation of the technology's presence and exposure within the environment is necessary.

CVE advisoryCRITICAL

CVE-2026-15733

WGDashboard RCE via OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in WGDashboard allows authenticated attackers to execute arbitrary OS commands as root, potentially leading to a full system compromise. This impacts the web-based management interface for WireGuard VPNs, which is often internet-accessible, making it a significant concern for environments using

CVE advisoryCRITICAL

CVE-2026-15732

WGDashboard SSRF Vulnerability Allows Arbitrary HTTP Requests

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Request Forgery vulnerability exists in WGDashboard, allowing authenticated attackers to make arbitrary HTTP requests and retrieve responses. This could lead to unauthorized access to sensitive information or internal systems. Confirmation of deployment and exposure is advised.

CVE advisoryCRITICAL

CVE-2026-14812

Premium SEO WordPress Plugin Backdoor Allows Full Site Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Premium SEO WordPress plugin, enabling unauthenticated attackers to achieve full site control via a hidden backdoor. This backdoor can create hidden administrator accounts and may allow remote code execution, posing a significant risk to website integrity.

CVE advisoryCRITICAL

CVE-2026-11976

MonsterInsights Pro Compromised Update Distribution Supply Chain Compromise

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The official update distribution for MonsterInsights Pro was compromised, allowing malicious files to be included in legitimate plugin updates. This supply chain issue means organizations updating the plugin could unknowingly install harmful code, potentially affecting website operations and data integrity. The exact i

CVE advisoryCRITICAL

CVE-2025-14561

Publisher API Tenant Isolation Bypass in Multi-Tenant Deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Publisher REST APIs within multi-tenant deployments, allowing a privileged user to perform operations impacting other tenants. This could lead to unauthorized exposure or modification of API metadata in different tenant environments. The impact is realized only in multi-tenant configurations w

CVE advisoryCRITICAL

CVE-2026-66709

CTX Feed Plugin Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the CTX Feed plugin. If reachable, an attacker with shop manager privileges could exploit this to run arbitrary code on the server. This could impact the integrity and availability of the shop manager service.

CVE advisoryCRITICAL

CVE-2026-66665

Type Hub Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated arbitrary file upload vulnerability in Type Hub could permit attackers to upload malicious files, potentially leading to system compromise. This issue is relevant if the technology is reachable externally, and the potential impact of successful exploitation warrants attention. Uncertainty exists rega

CVE advisoryCRITICAL

CVE-2026-66662

DynamiApps Frontend Admin Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated privilege escalation vulnerability exists in a frontend administrative tool, potentially allowing unauthorized users to gain administrative control. This could lead to unauthorized access and modification of system data or service behavior if the component is externally reachable. Confirmatio

CVE advisoryCRITICAL

CVE-2026-65579

Agricola Theme PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in the Agricola theme. This flaw could allow an attacker to inject malicious PHP objects, potentially leading to unauthorized code execution or data manipulation on public-facing websites. Confirmation of the theme's presence and exposure is necessary to asse

CVE advisoryCRITICAL

CVE-2026-65578

Agora Theme PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Agora WordPress theme, allowing attackers to inject malicious code. This could lead to the execution of arbitrary code on the server and compromise website integrity. It is important to determine if affected versions are in use within your environment.

CVE advisoryCRITICAL

CVE-2026-65577

Advice Theme PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Advice theme, potentially allowing attackers to execute arbitrary code remotely. This issue is reachable via the network, posing a significant risk to web applications. Confirming its presence and assessing exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-65576

Adrena Theme PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability in Adrena themes can allow unauthenticated attackers to inject malicious code via network requests, potentially leading to arbitrary code execution and compromise of system data. Confirmation of Adrena theme usage within the environment is the primary concern.

CVE advisoryCRITICAL

CVE-2026-65575

Accalia Theme Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in Accalia, which could allow an attacker to execute arbitrary code without authentication. This vulnerability is critical and has a network attack vector, meaning it could be reachable from the internet. Organizations should identify and assess their exposur

CVE advisoryCRITICAL

CVE-2026-65574

Abogado Theme PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Abogado theme. If reachable, this flaw could allow attackers to inject malicious code, potentially leading to a complete compromise of the affected application. Organizations should verify if this theme is deployed to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-65573

Abelle Theme Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability in Abelle software allows unauthenticated attackers to execute arbitrary code, potentially leading to full system compromise. This issue is reachable via network, making it an external threat that requires confirmation of Abelle's presence and assessment of potential exposu

CVE advisoryCRITICAL

CVE-2026-65572

PHP Object Injection in A.Williams Theme Versions Prior to 1.3.2

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in an unauthenticated PHP object injection flaw within a WordPress theme. If reachable, an attacker could execute arbitrary code, potentially leading to full website compromise. Confirming affected systems and assessing potential exposure is crucial for understanding the risk.

CVE advisoryCRITICAL

CVE-2026-65571

69 Clothing Theme PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability in the 69 Clothing theme allows attackers to inject malicious code by sending crafted requests, potentially leading to unauthorized access and system compromise. This issue is externally exploitable and poses a critical risk to the confidentiality and integrity of a

CVE advisoryCRITICAL

CVE-2026-65556

WPBruiser No-Captcha Anti-Spam Unauthenticated PHP Object Injection CVE-2026-65556

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in an anti-spam plugin. This could allow attackers to inject malicious code, potentially leading to system compromise. The presence and exposure of this plugin within the environment are key concerns.

CVE advisoryCRITICAL

CVE-2026-65553

Spider Analyser WordPress Plugin Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote code execution vulnerability exists in the Spider Analyser WordPress plugin. Attackers can exploit this critical issue over the network without authentication, potentially leading to arbitrary code execution and full server compromise. Confirming the use and exposure of this plugin is essentia

CVE advisoryCRITICAL

CVE-2026-65552

Subscriber PHP Object Injection in Export User Data Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP object injection vulnerability exists in the Export User Data WordPress plugin, potentially allowing unauthenticated attackers to inject malicious code. This could lead to sensitive data disclosure, modification, or service disruption if the plugin is used and reachable. Confirming its presence and asses

CVE advisoryCRITICAL

CVE-2026-65548

Betheme Contributor Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Betheme WordPress theme could permit a contributor-level user to execute arbitrary code remotely. This could lead to a full compromise of the website's server if the theme is internet-facing. Confirmation of Betheme usage and its exposure is important.

CVE advisoryCRITICAL

CVE-2026-65546

Qode Tours Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Qode Tours plugin. This flaw could allow an attacker to inject malicious SQL commands, potentially leading to unauthorized access to sensitive data. Organizations should verify if they are using this plugin and assess the associated risk.

CVE advisoryCRITICAL

CVE-2026-65520

WP OAuth Server SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability in the WP OAuth Server plugin could allow attackers to access or modify sensitive data. This issue is relevant to systems using this plugin for authentication and authorization, potentially impacting database integrity and service availability.

CVE advisoryCRITICAL

CVE-2026-65508

Simply Schedule Appointments SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Simply Schedule Appointments plugin, potentially allowing attackers to access or modify sensitive database information. This external threat requires confirmation of the plugin's presence and reachability on your network to assess relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-65507

AIWU Plugin Unauthenticated Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the AIWU plugin, allowing unauthenticated attackers to escalate privileges. If reachable, this could lead to unauthorized access and system control. Organizations using the affected technology should confirm relevance and potential exposure.

CVE advisoryCRITICAL

CVE-2026-54489

Dell VSI for VMware Information Disclosure and Session Hijacking

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A sensitive information disclosure vulnerability exists in Dell Virtual Storage Integrator for VMware vSphere Client that could allow an unauthenticated remote attacker to steal session credentials, leading to full user impersonation. This impacts the ability to manage virtual storage and requires immediate attention.

CVE advisoryCRITICAL

CVE-2026-53976

OpenChamber Path Traversal Allows Arbitrary File Read and Authentication Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenChamber's file-serving functions contain a path traversal flaw that lets unauthenticated remote attackers read sensitive files by bypassing security checks. This could lead to unauthorized access and authentication bypass by exposing critical information like secrets and credentials.

CVE advisoryCRITICAL

CVE-2026-53975

OpenChamber Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated remote code execution vulnerability exists in OpenChamber, allowing attackers to run arbitrary shell commands by sending specific POST requests to an API endpoint. This could lead to unauthorized system control and access to sensitive information.

CVE advisoryCRITICAL

CVE-2026-32327

APR-util Stack Recursion Vulnerability in XML Parsing

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stack recursion vulnerability exists in APR-util when parsing XML from untrusted sources with a specific function. If reachable, this could lead to denial-of-service or code execution. The risk depends on how systems process external XML using this library function.

CVE advisoryCRITICAL

CVE-2026-28139

Ajax Search Lite PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in Ajax Search Lite, potentially allowing attackers to inject malicious objects, leading to arbitrary code execution and system compromise. This poses a risk to website integrity and confidentiality. The relevance and exposure of this vulnerability within our

CVE advisoryCRITICAL

CVE-2026-28005

Kadence WooCommerce Email Designer Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the Kadence WooCommerce Email Designer plugin, potentially allowing attackers to gain elevated system privileges. This could impact website data and administrative control, requiring confirmation of the plugin's usage and exposure to assess risk.

CVE advisoryCRITICAL

CVE-2026-64993

Dell RVTools Improper Certificate Validation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper certificate validation vulnerability in Dell RVTools may allow an unauthenticated remote attacker to compromise data confidentiality and integrity. The vulnerability resides in the collector component and could be exploited if reachable. It is uncertain if this technology is in use or its potential impact.

CVE advisoryCRITICAL

CVE-2026-5134

CMS SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in a Content Management System, potentially allowing attackers to manipulate database queries and gain unauthorized access to data. The vendor has not responded to inquiries about this issue, and its reachability over the network poses a risk to system integrity and data co

CVE advisoryCRITICAL

CVE-2026-12605

Eclipse GlassFish DownloadServlet Vulnerability Allows Unauthenticated Domain Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Eclipse GlassFish that could allow an unauthenticated attacker to gain full control of the administrative domain by leaking an administrator's authentication token. This could occur if an authenticated user is tricked into interacting with a malicious resource. Organizations should de

CVE advisoryCRITICAL

CVE-2026-65583

Apache CXF OIDC Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Apache CXF's OIDC relying-party token validation that could allow an attacker to bypass authentication by using crafted tokens. Although the acceptance of self-issued ID tokens is not enabled by default, if configured, this could permit unauthorized access. Understanding if this feature is act

CVE advisoryCRITICAL

CVE-2026-63687

Apache CXF JWT Filter Flaw Undermines PKCE and OpenID Connect Integrity.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache CXF's JWT filter improperly copies sensitive claims from signed requests, allowing an attacker with a compromised secret to potentially undermine PKCE and OpenID Connect replay protection. This could impact systems handling authentication and authorization.

CVE advisoryCRITICAL

CVE-2026-61466

Apache CXF OAuth2 Client Registration Vulnerability Allows Privileged Scope Assignment.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Apache CXF's OAuth2 Dynamic Client Registration endpoint allows for unvalidated scope assignments, potentially enabling clients to self-assign privileged scopes. This could impact access control if the endpoint is reachable. The relevance and exposure of this issue should be confirmed.

CVE advisoryCRITICAL

CVE-2026-66909

Apache CXF JMS Transport Deserialization Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Apache CXF's JMS transport is vulnerable to remote code execution and denial of service through insecure deserialization of inbound messages. Attackers can exploit this by sending malicious serialized objects to the JMS destination, potentially compromising affected systems without authentication. Confirming the usage

CVE advisoryHIGH

CVE-2026-57817

Apache CXF OpenID Connect Authorization Code Substitution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Apache CXF when using OpenID Connect Hybrid Flow with misconfigured identity providers that omit the `c_hash` parameter. This could allow attackers to substitute or inject authorization codes, potentially leading to unauthorized access. It is important to determine if affected systems are rele

CVE advisoryCRITICAL

CVE-2026-5430

JWT Algorithm Downgrade Authentication Bypass.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in JWT authentication allows attackers to bypass security controls by using unsupported signing algorithms, potentially leading to unauthorized access and account takeover. This issue, which does not require prior authentication to exploit, could expose system data and administrative accounts. Its natur

CVE advisoryCRITICAL

CVE-2026-1728

WSO2 Admin REST API Token Restriction Bypass Allows Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in WSO2 products allows low-privileged users to access administrative APIs using improperly restricted tokens, potentially leading to full administrative account takeover. This issue is relevant if an attacker already possesses a low-privileged user account and can obtain a valid token.

CVE advisoryCRITICAL

CVE-2025-15039

Conditional Authentication Bypass Allows Account Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Conditional Authentication scripts can allow attackers to bypass intermediate authentication steps, leading to unauthorized access to user accounts when specific multi-step authentication configurations and certain authenticators are in use. This affects a critical system for controlling access to ap

CVE advisoryCRITICAL

CVE-2026-16054

WooCommerce File Upload Plugin Deletes Order Attachments

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can use a vulnerability in a WooCommerce WordPress plugin to delete customer order attachments, irreversibly destroying pending order information. The issue stems from an insufficient control on the file-deletion routine, allowing anonymous attackers to obtain a valid nonce and remove files

CVE advisoryCRITICAL

CVE-2026-12713

WPCargo Track & Trace SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A WordPress plugin flaw allows unauthenticated users to inject SQL, potentially leading to unauthorized access or modification of sensitive database information. This vulnerability is reachable via the public web and poses a risk to data integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-67873

lib60870 Heap-Based Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in lib60870's FileSegment encoding allows specially crafted data to overflow a buffer, potentially corrupting memory and impacting service availability and integrity. If reachable, this vulnerability could lead to denial of service or code execution. Understanding the exposure and criticali

CVE advisoryCRITICAL

CVE-2026-67870

Open62541 Null Pointer Dereference in AddReferences Affects Server Operation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in open62541's server-side AddReferences implementation allows a remote attacker to send a crafted request, potentially leading to a NULL pointer dereference. This could affect service availability and data integrity. It is uncertain if this technology is used or exposed in your environment, requiring confirmati

CVE advisoryCRITICAL

CVE-2026-67531

FrontMCP Sandbox Escape Allows Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

FrontMCP, a framework for Model Context Protocol, has a vulnerability that allows attackers to execute arbitrary code on the server. This occurs because the sandboxed code execution feature incorrectly exposes Zod schema instances, enabling scripts to access the host's Function constructor and run unauthorized commands

CVE advisoryCRITICAL

CVE-2026-52466

VuFind Incorrect Access Control Allows Function Execution Despite Denial

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

VuFind's incorrect access control allows unauthorized users to execute functions even after access is denied, posing a critical risk. This vulnerability is reachable via the network and could lead to the execution of sensitive operations. It is important to confirm if VuFind is used within the organization and assess a