NVD disclosure day

Published threat advisories for August 11, 2026

CVE advisoryCRITICAL

CVE-2026-13716

Crafty Controller Path Traversal Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Crafty Controller's server import and admin file upload functions allows authenticated attackers to upload files to arbitrary paths, potentially leading to remote code execution. This could impact the confidentiality, integrity, and availability of managed services.

CVE advisoryCRITICAL

CVE-2026-19425

Win Men Travel Agency Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a Travel Agency Management System, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This could lead to the unauthorized reading, modification, or deletion of database contents. Confirmation of the system's relevance and network exposure is critical for

CVE advisoryCRITICAL

CVE-2026-44758

SAP MII Command Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in SAP Manufacturing Integration and Intelligence allows a high-privilege attacker to execute arbitrary commands on the operating system due to insufficient input validation. This could severely impact the application's confidentiality, integrity, and availability, requiring confirmation of MII

CVE advisoryCRITICAL

CVE-2026-34265

SAP NetWeaver AS ABAP DIAG Protocol Memory Corruption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker can exploit memory corruption flaws in SAP NetWeaver Application Server ABAP's DIAG protocol parsing, potentially leading to sensitive information disclosure or system crashes. This impacts confidentiality, integrity, and availability.