NVD disclosure day

Published threat advisories for August 7, 2026

CVE advisoryCRITICAL

CVE-2026-46409

OpenYak RCE via Local HTTP API Insecure Binding

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The OpenYak desktop application has a vulnerability where its local HTTP API lacks server-side validation, allowing a malicious webpage visited by a user to execute arbitrary shell commands and exfiltrate sensitive data. This could lead to remote code execution and compromise of user information.

CVE advisoryCRITICAL

CVE-2026-48170

SCIM Patch Prototype Pollution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A prototype pollution vulnerability exists in the `scim-patch` library, allowing an attacker to modify global objects in a Node.js process via specially crafted SCIM PATCH requests. This could affect services processing external SCIM PATCH operations, potentially impacting system data and behavior.

CVE advisoryCRITICAL

CVE-2026-50540

Kata Containers host code execution via unvalidated configuration path

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Kata Containers, an open-source project for containerized virtual machines, has a vulnerability where an unvalidated configuration path annotation allows a user within a pod to execute arbitrary code as root on the host. This occurs when a pod user can place a file at a host-visible path and supply a configuration poin

CVE advisoryCRITICAL

CVE-2026-61808

LightRAG API Authentication Bypass Allows Unauthorized Document Access and Control

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in LightRAG's API server allows unauthenticated network attackers to access sensitive documents, alter data, and disrupt system operations. This occurs because the server binds to all network interfaces by default with disabled authentication. If reachable, this could lead to unauthorized data exposure

CVE advisoryCRITICAL

CVE-2026-71851

Insecure Randomness in crypto-js Affects Wallet Security.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a JavaScript cryptography library allows predictable random number generation, potentially enabling attackers to discover private keys and gain control of cryptocurrency funds if the library is used for recovery phrases. This issue is addressed in version 4.0.0.

CVE advisoryCRITICAL

CVE-2026-19264

Postiz Unauthenticated Directory Traversal Leads to Session Forgery.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can exploit a path traversal vulnerability in Postiz, an open-source social media scheduling tool, to read sensitive files. This vulnerability allows attackers to access critical information, such as JWT signing secrets and database connection strings, enabling them to forge session t

CVE advisoryCRITICAL

CVE-2022-4995

Weaver E-cology File Upload Vulnerability Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A file upload vulnerability in the Weaver E-cology platform enables unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the application server. This could compromise the confidentiality, integrity, and availability of the application and its data. It is important to conf

CVE advisoryCRITICAL

CVE-2026-66914

SEBLOD Unauthenticated Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated path traversal vulnerability in a Joomla extension could allow attackers to download sensitive files from a web server. This issue may expose information both inside and outside the webroot, depending on the extension's usage. Understanding the relevance of this extension in your environment is cruci

CVE advisoryCRITICAL

CVE-2026-56793

Dell OpenManage Server Administrator Improper Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authentication vulnerability in Dell OpenManage Server Administrator could allow an unauthenticated attacker with remote access to gain unauthorized system control. This is a concern because the affected software is used for server management, and exploitation could lead to unauthorized access to critical s

CVE advisoryCRITICAL

CVE-2026-71558

Apache Fory C++ Deserialization Type Confusion Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap type confusion vulnerability exists in Apache Fory C++ deserialization, potentially allowing denial of service or arbitrary code execution if reachable. This issue arises from bypassing type compatibility checks during polymorphic smart-pointer deserialization. Its relevance depends on whether applications utili

CVE advisoryCRITICAL

CVE-2026-54213

TeamDavid Webbox Unauthenticated Denial of Service Shutdown

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can remotely shut down the TeamDavid Webbox application, causing a persistent denial of service that requires manual administrator intervention to resolve. This vulnerability is accessible to unauthenticated users over the public internet.

CVE advisoryCRITICAL

CVE-2026-54212

Tobit David's Webbox API Buffer Overflow Leads to Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow in Tobit David's Webbox application's API endpoint could allow an unauthenticated attacker to crash the server, causing a denial of service. Depending on other factors, this could potentially lead to remote code execution and full server compromise.

CVE advisoryCRITICAL

CVE-2026-54211

TeamDavid Webbox Endpoint Buffer Overflow Denial of Service Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

TeamDavid's Webbox application contains a buffer overflow vulnerability in its `//serverClient_close.html` endpoint that an authenticated attacker could exploit by submitting excessively long data. This could cause a server crash, leading to denial of service, and potentially enable remote code execution for full serve

CVE advisoryCRITICAL

CVE-2026-54210

TeamDavid Webbox File Upload Buffer Overflow Denial of Service

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A buffer overflow vulnerability exists in Tobit Laboratories AG's Webbox application's file upload functionality, which an unauthenticated attacker could exploit by uploading a file with an excessively long filename. This may lead to a denial of service by crashing the server, and under certain conditions, could potent

CVE advisoryCRITICAL

CVE-2026-54203

Tobit TeamDavid Webbox Memory Leak Exposes Sensitive Information

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A memory leak vulnerability in Tobit Laboratories AG TeamDavid's Webbox enables unauthenticated actors to read sensitive information, potentially including user passwords, by repeatedly accessing a specific URL. This could expose confidential data if the affected component is exposed and relevant.

CVE advisoryCRITICAL

CVE-2026-16258

Ajax Search Lite WordPress Plugin PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Ajax Search Lite WordPress plugin that allows unauthenticated attackers to inject PHP objects. This could lead to remote code execution if a specific chain of objects is available, potentially compromising the confidentiality, integrity, and availability of affected websites.

CVE advisoryCRITICAL

CVE-2026-16038

MStore API WordPress Plugin Order Paid Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The MStore API WordPress plugin has a critical vulnerability that allows unauthenticated attackers to bypass payment verification and obtain goods or services without payment. This could impact the integrity of sales transactions and lead to financial loss.

CVE advisoryCRITICAL

CVE-2026-14205

WP Events Manager Unauthenticated Free Booking Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The WP Events Manager WordPress plugin has a vulnerability that allows any authenticated user to create bookings for paid events without making a payment. This is due to the plugin not validating the requested quantity, enabling attackers to manipulate the price calculation. This could result in financial discrepancies

CVE advisoryCRITICAL

CVE-2026-14365

TrueBooker WordPress Plugin Authorization Bypass Allows Arbitrary Password Changes

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the TrueBooker WordPress plugin, allowing unauthenticated attackers to bypass authorization checks and change any user's password, including administrators. This could lead to account compromise and full takeover of WordPress sites. Confirmation of the plugin's use and exposure within

CVE advisoryCRITICAL

CVE-2026-14364

TrueBooker WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a WordPress appointment booking plugin allows unauthenticated attackers to take over any user account, including administrators, by exploiting a weakness in the password reset validation. This could lead to unauthorized access to account credentials and data. The reader should care because i

CVE advisoryCRITICAL

CVE-2026-70332

Microsoft SharePoint Server-Side Request Forgery Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Server-Side Request Forgery vulnerability in Microsoft Office SharePoint allows unauthorized attackers to perform network spoofing. If reachable, this could enable attackers to impersonate legitimate network traffic, potentially leading to unauthorized actions or access to sensitive information. The relevance of this

CVE advisoryCRITICAL

CVE-2026-68823

Azure Confidential Ledger Exposed Dangerous Method Leading to Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Azure Confidential Ledger has a vulnerability where an authorized attacker with network access could execute code. This could affect the integrity and confidentiality of data handled by this service. Review its presence and impact on your environment.

CVE advisoryCRITICAL

CVE-2026-65667

Microsoft Teams Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Microsoft Teams due to missing authorization, potentially allowing network attackers to elevate privileges. This affects a widely used, internet-connected collaboration tool, posing a risk to data confidentiality and integrity if exploited.

CVE advisoryCRITICAL

CVE-2026-63508

Microsoft Planetary Computer Pro Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Microsoft Planetary Computer Pro allows unauthorized attackers to elevate privileges over a network due to missing authentication for a critical function. This could lead to unauthorized actions within the platform. It is uncertain if your organization uses this technology.

CVE advisoryCRITICAL

CVE-2026-62896

Microsoft Teams Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Microsoft Teams has an improper authentication vulnerability that could allow an authorized attacker to elevate privileges over a network. This means an attacker with existing access could gain higher-level control. Understanding if your organization uses Teams and if it is reachable is important.

CVE advisoryCRITICAL

CVE-2026-62873

Microsoft 365 Admin Center Privilege Escalation via Improper Signature Verification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper verification of cryptographic signatures in the Microsoft 365 Admin Center allows an unauthorized network attacker to elevate privileges. This could lead to unauthorized access and modification of sensitive settings or data.

CVE advisoryCRITICAL

CVE-2026-62836

Azure SQL Managed Instance Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An Azure SQL Managed Instance vulnerability allows an unauthorized attacker to elevate privileges over a network by improperly restricting communication channels. This could impact service behavior and lead to unauthorized access to system data. Confirmation of the service's usage and network exposure is necessary to u

CVE advisoryCRITICAL

CVE-2026-62830

Azure SRE Agent Missing Authorization Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A missing authorization vulnerability in Azure SRE Agent could permit a network-based attacker with some level of access to elevate privileges. This could lead to unauthorized control over systems managed by the agent, impacting confidentiality and integrity. Given its potential for significant compromise, understandin

CVE advisoryCRITICAL

CVE-2026-59118

Microsoft Power Apps Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability in Microsoft Power Apps could allow an unauthorized attacker to elevate privileges over a network. This could lead to an attacker gaining higher levels of control, potentially impacting system and user data. It is important to determine if your organization uses the affected tech

CVE advisoryCRITICAL

CVE-2026-59115

Microsoft Entra Provisioning Service Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Microsoft Entra Provisioning Service that allows an authorized attacker to elevate privileges over a network. This could impact identity and access management if the affected service is reachable. Confirmation of your environment's exposure and relevant ownership is key to understanding the ri

CVE advisoryCRITICAL

CVE-2026-56162

Azure SQL Database Privilege Escalation via Improper Authentication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Improper authentication in Azure SQL Database allows an unauthorized attacker to gain elevated privileges over a network. This could potentially lead to unauthorized access, modification, or deletion of sensitive data. Readers should verify the exposure of their Azure SQL Database instances and consider the potential b

CVE advisoryCRITICAL

CVE-2026-56161

Azure Logic Apps Improper Access Control Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper access control vulnerability in Azure Logic Apps allows an authorized attacker to disclose sensitive information over a network. This could result in unauthorized access to data handled by the Logic App, increasing the potential impact due to the service's role in system integration and data processing.

CVE advisoryCRITICAL

CVE-2026-50515

Azure Service Bus Deserialization Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authorized attacker with network access to Azure Service Bus could execute code, impacting confidentiality, integrity, and availability. This critical vulnerability in a messaging service allows remote code execution when processing untrusted data. Confirming the relevance and exposure of Azure Service Bus deploymen

CVE advisoryCRITICAL

CVE-2026-50481

Azure Active Directory Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Azure Active Directory may allow an authorized attacker to elevate privileges over a network by modifying data that should be immutable. This impacts a core, internet-facing identity and access management service. This could lead to compromised system integrity and unauthorized actions. Conf