NVD disclosure day

Published threat advisories for August 10, 2026

CVE advisoryCRITICAL

CVE-2026-48161

react18-use Malicious Commits Execute Remote Code on Developer Machines

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `react18-use` project's default branch contained malicious commits that could execute remote attacker-controlled code on developer machines during `npm install`. While the malicious commits were removed and the package was not published, local clones or forks of the affected code could still pose a risk, potentiall

CVE advisoryCRITICAL

CVE-2026-72911

ERPNext Unrestricted Template Injection Leading to Server-Side Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ERPNext allows authenticated users to inject template expressions, leading to arbitrary server-side code execution and data access. This impacts the confidentiality and integrity of application data, making it crucial to confirm the relevance and exposure of deployed instances.

CVE advisoryCRITICAL

CVE-2026-72904

Firecrawl Arbitrary File Read and SSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Firecrawl's extraction functionality allows arbitrary file reads and server-side request forgery. An attacker can exploit this by providing a malicious JSON schema, potentially exposing sensitive files or internal systems. This issue impacts the core data processing capabilities of the appli

CVE advisoryCRITICAL

CVE-2026-48160

react-tracked Malicious Commits Execute Code on Developer Machines During npm Install

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security vulnerability in a development tool allows attackers to execute arbitrary code on developer machines during `npm install` via malicious commits. While removed from the main branch, affected local copies could still lead to full compromise of anything reachable by the Node process. Verify developer machine ex

CVE advisoryCRITICAL

CVE-2026-18948

Feast Registry Deserialization Vulnerability Allows Arbitrary Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Feast allows attackers to execute arbitrary code on feature and registry servers through improperly deserialized user-defined functions. This could lead to unauthorized cross-tenant data access and lateral movement within the system.

CVE advisoryCRITICAL

CVE-2026-14450

MaaS API Header Forgery Allows Unauthorized Access and Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A MaaS API vulnerability allows internal applications to bypass authentication by forging HTTP headers, leading to unauthorized access and privilege escalation. This could enable an attacker to mint tokens in other namespaces, revoke API keys, or exfiltrate sensitive configurations. The issue is relevant if your enviro

CVE advisoryCRITICAL

CVE-2026-72902

Dokploy Authenticated Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy allows an authenticated user to execute arbitrary commands on target servers by interpolating a password field into a shell command. This could affect systems managing application deployments. The primary concern is confirming if Dokploy is in use and if it is reachable.

CVE advisoryCRITICAL

CVE-2026-72901

Dokploy Command Injection Vulnerability Affects Control Plane Hosts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy, a self-hostable PaaS, has a vulnerability that allows authenticated low-privilege users to run arbitrary commands on the control plane. This occurs due to improper handling of the `volumeName` field in backup operations, which, with Docker socket access, can lead to host or root-equivalent privileges. This cou

CVE advisoryCRITICAL

CVE-2026-72886

Dokploy Schedule Root Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hosted Platform as a Service, allows authenticated users to execute arbitrary scripts with root privileges by manipulating schedule updates. This could lead to unauthorized system access and control if the technology is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-72882

Dokploy Command Injection via File Mounts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hostable Platform as a Service, allows an authenticated user to inject shell commands via file mounts, potentially leading to arbitrary command execution on remote managed servers. Exploitation could result in a compromise of the server's integrity and confidentiality. Readers should

CVE advisoryCRITICAL

CVE-2026-72880

Dokploy Certificate Path Traversal leads to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Dokploy, a self-hostable PaaS, allows an authenticated user to write or delete files outside intended directories by manipulating a certificate path. This could impact the integrity and availability of managed services and the underlying system.

CVE advisoryCRITICAL

CVE-2026-72879

Dokploy Command Injection Vulnerability via Malicious Registry Credentials.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Dokploy, a self-hosted Platform as a Service, where an authenticated user can execute arbitrary OS commands on the server by providing malicious registry credentials. This could allow unauthorized access to host files and other containers. Dokploy is typically internet-facing, making it a pote

CVE advisoryCRITICAL

CVE-2026-72878

Dokploy Command Injection in Backup Restore Pipeline

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in Dokploy allows authenticated administrators to execute arbitrary OS commands on the host system. This occurs because user-controlled database fields are interpolated into shell commands without proper sanitization during the backup and restore process. This could lead to host system

CVE advisoryCRITICAL

CVE-2026-72877

Dokploy Docker Image Field Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy, a self-hostable PaaS, has a vulnerability where an authenticated user with application create/update permissions can inject commands into the `dockerImage` field, potentially leading to arbitrary command execution on the build host. This could expose sensitive host secrets and other projects. The issue is fixe

CVE advisoryCRITICAL

CVE-2026-72876

Dokploy Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy, a self-hostable PaaS, has a vulnerability allowing unauthorized command execution on other tenants' servers. This could compromise server integrity and data, impacting hosted services. Confirm if your Dokploy environment is affected and assess its exposure to mitigate risks.

CVE advisoryCRITICAL

CVE-2025-15681

TBEA TLogger Authentication Bypass and Server Crash

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in TLogger devices' web server, allowing unauthenticated attackers to access protected functionality through a specific endpoint. This could expose or modify device configuration and data, and in some cases, logging out after exploitation may crash the server.

CVE advisoryCRITICAL

CVE-2025-13294

TBEA TLogger SQL Injection Allows Database Tampering

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in the TBEA TLogger web server allows remote attackers to read, modify, or delete data in the device's database. The flaw enables manipulation of SQLite queries through HTTP endpoints, potentially impacting data integrity and availability.

CVE advisoryCRITICAL

CVE-2025-13293

TBEA TLogger SSH Root Access via Hard-coded Credentials

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hard-coded root credential in TBEA TLogger's SSH service allows unauthenticated remote attackers to gain full administrative control of the device. This vulnerability, identified as critical, could lead to unauthorized system takeover and compromise of device functions. Readers should confirm the relevance and assess

CVE advisoryCRITICAL

CVE-2026-72872

Dokploy OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Dokploy, a self-hosted PaaS, allows authenticated users with deployment permissions to execute arbitrary OS commands. This occurs due to unvalidated Bitbucket provider input, enabling potential host system compromise. Confirming its use and reachability is essential.

CVE advisoryCRITICAL

CVE-2026-72869

Dokploy Remote Code Execution via Crafted Database Name

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Dokploy allows authenticated users with backup restore permissions to execute arbitrary commands on the host system. This occurs due to improper handling of a crafted database name during the backup restore process, enabling command injection within the Docker-privileged host context. Organi

CVE advisoryCRITICAL

CVE-2026-72868

Dokploy Destination Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hosted Platform as a Service, allows low-privileged users to execute arbitrary commands. This occurs when testing destination connections, potentially leading to unauthorized command execution within the Dokploy container and impacting the host system. Dokploy is a free, self-hostable

CVE advisoryCRITICAL

CVE-2026-72867

Dokploy PaaS Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Dokploy, a self-hostable PaaS, allowing a low-privileged authenticated user to execute arbitrary host commands. This is possible because certain custom branch fields lack server-side validation and are later used in Git commands during deployments. This could impact the confidentialit

CVE advisoryCRITICAL

CVE-2026-72865

Dokploy Command Injection Vulnerability Affects Self-Hosted PaaS

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hostable platform for managing deployments, allows an authenticated user with specific permissions to execute arbitrary operating-system commands on the host system by supplying a crafted path during deployment operations. This could impact the integrity and availability of the host e

CVE advisoryCRITICAL

CVE-2026-72864

Dokploy Container Root Shell Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hostable Platform as a Service, allows authenticated users to gain root-level access to arbitrary containers on a self-hosted instance. This could lead to a significant compromise of deployed applications and services within the affected environment. The issue has been addressed in ve

CVE advisoryCRITICAL

CVE-2026-72899

Metabase Unauthenticated SQL Injection via Shared Cards

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Metabase has a critical vulnerability allowing unauthenticated SQL injection through publicly shared content. This could lead to unauthorized data access or manipulation. Organizations using Metabase should assess if publicly shared cards or dashboards with field-filter parameters are exposed.

CVE advisoryCRITICAL

CVE-2026-72862

Dokploy Command Injection in Database Deployment Functions

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Dokploy's database deployment functions where unquoted user input can lead to command injection on the remote server. This could allow an authenticated attacker to execute arbitrary commands, potentially compromising the system and its data. Organizations using Dokploy should confirm

CVE advisoryCRITICAL

CVE-2026-72738

Dokploy Backup Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy, a self-hostable PaaS, contains a vulnerability in its backup endpoint that allows an authenticated user with backup read permissions to execute arbitrary commands on the host. This occurs when a search parameter is processed and interpolated into a server-side command. Exploitation could lead to unauthorized c

CVE advisoryCRITICAL

CVE-2026-72737

Dokploy Organization Data Exposure and Backup Poisoning Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Dokploy, a self-hostable Platform as a Service, allows authenticated users with backup permissions to access or poison backup data from other organizations. This occurs because the system accepts a client-controlled destination ID without proper verification of the organization associated with that d

CVE advisoryCRITICAL

CVE-2026-72736

Dokploy Command Injection via Unquoted Shell Interpolation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Dokploy, a self-hosted PaaS, allows authenticated users to execute arbitrary commands remotely by sending specially crafted input to specific management endpoints. This could lead to system compromise and disruption of managed services. Confirming Dokploy's presence and exposure is crucial f

CVE advisoryCRITICAL

CVE-2026-72733

Dokploy Command Injection Vulnerability in Restore Functionality

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dokploy, a self-hostable PaaS, contains a critical vulnerability where an authenticated user with backup-restore permissions can inject operating-system commands into the host environment. This occurs because the backup restoration process improperly handles user-provided fields, allowing for shell command injection ev

CVE advisoryCRITICAL

CVE-2026-48159

use-reducer-async Malicious Commits Execute Remote Code on Developer Machines During npm Install

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Malicious commits in the `use-reducer-async` package executed attacker-controlled code on developer machines during `npm install`. Although removed from the default branch, local clones may still be affected, potentially leading to full compromise of the developer workstation. The vulnerability targeted developer envir

CVE advisoryCRITICAL

CVE-2026-16626

JasperReports Server XML External Entity Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in Jaspersoft JasperReports Server allows improper restriction of XML external entity references, potentially enabling attackers to access or manipulate data. This issue could affect system and sensitive information when the server is reachable over a network. Technical readers and secu

CVE advisoryHIGH

CVE-2026-66738

SPIP SQLite Code Injection via Navigation Menu

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SPIP installations using SQLite are vulnerable to code injection via the navigation menu endpoint. An authenticated attacker with editor privileges can execute arbitrary operating system commands on the web server by sending a crafted GET request. MySQL-backed installations are not affected. You should care if your SQL

CVE advisoryCRITICAL

CVE-2026-48158

use-context-selector Malicious Commits Compromise Developer Machines During Install

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security vulnerability in a React hook allowed remote code execution on developer machines during `npm install` via malicious commits. Though removed from the main branch, these commits may exist in local clones, enabling the execution of attacker-controlled code. This issue targets developer workstations, potentiall

CVE advisoryCRITICAL

CVE-2026-47754

Metacat Unauthenticated Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Metacat, data repository software, has an unauthenticated path traversal vulnerability in its API that allows attackers to read any file accessible to the hosting process. This could expose sensitive research data, credentials, and system information, potentially enabling impersonation and data disclosure.

CVE advisoryCRITICAL

CVE-2026-63106

ReadyEcommerce Unauthenticated SQL Injection Affecting Product Listing API.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the product listing API of ReadyEcommerce software. Attackers can exploit this by manipulating the rating parameter to extract sensitive database contents, including user credentials and administrator password hashes, potentially leading to unauthorized system ac

CVE advisoryHIGH

CVE-2026-19429

Jenkins FilePath Symlink Vulnerability Allows RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Jenkins FilePath.untarFrom() allows authenticated users to achieve remote code execution by exploiting improper validation of symbolic link targets during tar extraction. This could enable attackers to create symlinks to sensitive files, leading to the decryption of credentials and administr

CVE advisoryCRITICAL

CVE-2026-72593

Dulldusk PHP File Manager Unauthenticated Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in a file management tool that allows unauthenticated remote attackers to access, modify, or delete files anywhere on the server. This occurs due to a default configuration that bypasses authentication checks, granting full file management functionality without credentials.

CVE advisoryCRITICAL

CVE-2026-72589

Crontab-UI Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability exists in crontab-ui, allowing unauthenticated remote attackers to execute arbitrary system commands. This is possible by importing a crafted database file, which is not validated and can lead to command execution when cron jobs run. It is uncertain if this technology is used withi

CVE advisoryCRITICAL

CVE-2026-72580

Xiaomi Smart Speaker OS Command Injection via Mute Endpoint.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability in Xiaomi smart speaker software allows remote attackers to execute arbitrary system commands via network requests to specific API endpoints. This could lead to device compromise if the affected software is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-72577

NASA fprime-gds Unauthenticated Code Execution and Command Injection Vulnerabilities.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Multiple vulnerabilities in a NASA ground data system allow unauthenticated remote attackers to execute arbitrary code and inject commands to connected spacecraft. This could lead to a complete compromise of the system and any spacecraft it controls. It is uncertain if this technology is deployed or reachable in your e

CVE advisoryCRITICAL

CVE-2026-72575

Daptin Improper Authorization Vulnerability Allows Unauthenticated Usergroup Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability in daptin allows unauthenticated attackers to read, create, update, and delete usergroup records by bypassing permission checks. This could lead to unauthorized access to sensitive user group information, impacting data integrity and potentially business operations if daptin is u

CVE advisoryCRITICAL

CVE-2026-72569

Directory Serve Path Traversal Allows Arbitrary File Deletion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in a file-serving application allows unauthenticated remote attackers to delete arbitrary files outside the intended directory when a specific delete option is enabled, due to the application not sanitizing file path inputs. This could lead to unintended data removal if the vulnerable sof

CVE advisoryCRITICAL

CVE-2026-72567

AsyncFuncAI Deepwiki-Open Arbitrary File Write and Delete Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper path validation vulnerability in deepwiki-open could allow unauthenticated remote attackers to write to or delete arbitrary files with root privileges due to inadequate sanitization of user-controlled input in API endpoints. This could impact system integrity and data.

CVE advisoryCRITICAL

CVE-2026-72565

Tencent APIJSON SQL Injection Allows Database Table Reading

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in Tencent APIJSON, allowing unauthenticated remote attackers to read arbitrary database tables by bypassing access controls. This occurs due to an incomplete check of the "@having" operator in the APIJSONORM library. The potential impact includes unauthorized access to sensitive da

CVE advisoryCRITICAL

CVE-2026-72564

Improper Authorization in fosrl/pangolin Allows Token Reuse Across Organizations

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability exists in the pangolin software, enabling authenticated remote attackers to reuse an access token for any resource across different organizations. This occurs because the system fails to verify the token against the intended target resource, potentially leading to unauthorized ac

CVE advisoryCRITICAL

CVE-2026-19053

ProSolution WP Client Blind SQL Injection Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The ProSolution WP Client WordPress plugin contains a critical vulnerability that may allow unauthenticated visitors to execute blind SQL injection attacks. This could lead to unauthorized access to or modification of sensitive data stored in the website's database. This issue is a concern for any WordPress site using