NVD disclosure day

Published threat advisories for August 9, 2026

CVE advisoryCRITICAL

CVE-2026-18473

WP Directory Kit SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The WP Directory Kit WordPress plugin contains a critical SQL injection vulnerability that can be exploited by unauthenticated users. This flaw could allow attackers to access or modify sensitive data stored in the website's database. Given that WordPress sites are often publicly accessible, this issue warrants attenti

CVE advisoryCRITICAL

CVE-2026-15038

InfiniteWP Client Authentication Bypass Allows WordPress Network Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the InfiniteWP Client WordPress plugin could allow unauthenticated attackers to seize control of entire WordPress Multisite networks by hijacking administrator sessions, potentially leading to remote code execution. This issue arises from insufficient verification of requests to the plugin's remote-m

CVE advisoryCRITICAL

CVE-2026-71992

MSI Radix AXE6600 Command Injection via macfilter

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An MSI Radix AXE6600 router firmware vulnerability allows remote attackers to execute arbitrary commands and gain root privileges by exploiting the macfilter function. This command injection flaw could lead to a complete system compromise if the affected device is accessible.

CVE advisoryCRITICAL

CVE-2026-71991

MSI Radix AXE6600 Command Injection via Telnet Configuration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in MSI Radix AXE6600 router firmware allows remote attackers to execute arbitrary commands and gain root privileges. If the Telnet configuration interface is reachable, attackers can compromise the device, impacting network security and control.

CVE advisoryCRITICAL

CVE-2026-71990

MSI Radix AXE6600 Command Injection via TelnetSSH Function

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in the MSI Radix AXE6600 router's TelnetSSH function allows remote attackers to execute arbitrary commands and gain root privileges. This issue could potentially compromise the affected devices if their management interfaces are accessible, impacting network device security and managem

CVE advisoryCRITICAL

CVE-2026-71989

MSI Radix AXE6600 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware that allows remote attackers to execute arbitrary commands. If reachable, this could enable attackers to obtain root privileges on the affected device. This issue is relevant due to the router's role as an internet edge device.

CVE advisoryCRITICAL

CVE-2026-71988

MSI Radix AXE6600 Router Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MSI Radix AXE6600 router firmware contains a command injection vulnerability. Remote attackers can exploit this flaw to execute arbitrary commands and potentially gain root privileges on the device without authentication or user interaction. This poses a risk to device integrity and security.

CVE advisoryCRITICAL

CVE-2026-71987

MSI Radix AXE6600 Router Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware, allowing remote attackers to execute arbitrary commands and potentially gain root privileges. This is a concern because the vulnerability is reachable via the network, and successful exploitation could lead to full device control.

CVE advisoryCRITICAL

CVE-2026-71986

MSI Radix AXE6600 Command Injection via DMZ Function

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MSI Radix AXE6600 router firmware has a critical command injection vulnerability in its DMZ function, allowing unauthenticated remote attackers to execute arbitrary commands and gain root privileges. This issue, reachable via the network, impacts device control and overall network security. Organizations should identif

CVE advisoryCRITICAL

CVE-2026-71984

MSI Radix AXE6600 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware. This flaw allows remote attackers to execute arbitrary commands and potentially gain root privileges. As this affects a network edge device, it warrants careful consideration of potential exposure.