NVD disclosure day

Published threat advisories for August 11, 2026

CVE advisoryCRITICAL

CVE-2026-5917

libgit2 SSH Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in libgit2 when built with the libssh2 SSH backend, allowing remote attackers to execute arbitrary commands on an SSH server. This can occur if a user clones a malicious repository containing crafted submodule URLs with unescaped shell metacharacters, leading to command injection on the server. T

CVE advisoryCRITICAL

CVE-2026-71290

Apache HttpComponents Client TLS Hostname Verification Bypass.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Apache HttpComponents Client may allow an attacker to impersonate a server by presenting a valid certificate for a different domain when traffic is intercepted and modified. This occurs because the TLS hostname verification does not function as expected in the asynchronous version of the client. Orga

CVE advisoryCRITICAL

CVE-2026-66147

GMS Dispatcher Service Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated command injection vulnerability in the GMS Dispatcher Service may allow remote attackers to execute arbitrary code. This could impact systems running GMS 9.5.1 and earlier versions, potentially affecting confidentiality, integrity, and availability. Teams responsible for application security and infr

CVE advisoryCRITICAL

CVE-2026-73034

DB-GPT Path Traversal Arbitrary File Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated path traversal vulnerability in DB-GPT allows remote attackers to write arbitrary files to any server location by exploiting the file upload endpoint with a crafted HTTP header. This could lead to remote code execution if reachable. Assess your DB-GPT instances for exposure and criticality.

CVE advisoryCRITICAL

CVE-2026-73032

PapersGPT for Zotero RCE via Unsanitized LLM Response

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the PapersGPT for Zotero plugin, enabling remote code execution. Attackers can exploit this by providing malicious input to an LLM endpoint, allowing arbitrary JavaScript execution in a privileged context. This could lead to unauthorized access and modification of user data. The primary concer

CVE advisoryCRITICAL

CVE-2026-66145

GMS Zip Slip Vulnerability Allows Remote Code Execution and Data Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated remote code execution vulnerability in GMS allows attackers to read sensitive data and write arbitrary files. This could occur if the system is network-exposed and processes a crafted zip file. It is important to confirm if your organization uses this technology and is potentially at risk.

CVE advisoryCRITICAL

CVE-2026-45618

LiquidJS Arbitrary Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in LiquidJS, a template engine, allows arbitrary code execution through crafted templates. This could impact service integrity and availability, potentially exposing sensitive information if the affected technology is in use and reachable. Remediation is needed to address this risk.

CVE advisoryCRITICAL

CVE-2026-16230

Formidable Digital Signatures File Deletion Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Formidable Digital Signatures WordPress plugin has a file deletion vulnerability that unauthenticated attackers can exploit to delete arbitrary files on the server. This occurs when specific form submission parameters are manipulated. This could impact website integrity and availability if the plugin is used on a W

CVE advisoryCRITICAL

CVE-2026-72742

DSPy Local File Read via Image and Audio Output Adapters

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

DSPy's Image and Audio output adapters have a file exfiltration vulnerability that allows an attacker to read arbitrary local files by influencing language model outputs to include a filesystem path. The vulnerability occurs during the parsing of language model completions, which can embed sensitive file contents into

CVE advisoryCRITICAL

CVE-2026-73211

PeerTube SQL Injection Vulnerability Allows Database Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An SQL injection vulnerability in PeerTube allows unauthenticated attackers to read and write to its database, potentially enabling administrator account takeover. This impacts a federated video streaming platform, and its reachability means it could be targeted.

CVE advisoryCRITICAL

CVE-2026-73090

PeerTube Federated Video Metadata Rewriting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in PeerTube, a federated video streaming platform, allows a malicious server to rewrite another server's video metadata, visibility, and media file details. This could lead to unauthorized modifications of video content if the platform is reachable.

CVE advisoryCRITICAL

CVE-2026-71398

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability in Adobe Campaign Classic may permit an attacker to execute arbitrary code. This issue, which does not require user interaction, could impact system confidentiality, integrity, and availability. It is uncertain if this technology is present or exposed in our environment.

CVE advisoryCRITICAL

CVE-2026-69102

MaxKey JWT Signing Secret Vulnerability Allows Unauthorized Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MaxKey has an unauthorized access vulnerability due to a hard-coded JWT signing secret that allows unauthenticated attackers to forge tokens and gain administrative access. This could lead to the compromise of SSO application configurations and downstream secrets. You should care if MaxKey is deployed in your environme

CVE advisoryCRITICAL

CVE-2026-48381

Adobe Campaign Classic SQL Injection Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic has an SQL injection vulnerability that could allow an attacker to execute arbitrary code. Exploitation depends on conditions beyond an attacker's control, and it does not require user interaction. This impacts the confidentiality, integrity, and availability of systems.

CVE advisoryCRITICAL

CVE-2026-47705

TypeBot CSV Injection Executes Formulas in Exports

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

TypeBot's export function has a CSV injection vulnerability where unsanitized input can allow attackers to embed spreadsheet formulas. When an administrator opens an exported CSV containing these injected formulas, the formulas may execute, potentially leading to unauthorized actions or data compromise. This issue is p

CVE advisoryCRITICAL

CVE-2026-27302

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic has an authorization vulnerability allowing arbitrary code execution. An attacker could exploit this over the network without user interaction, potentially impacting system data and operations if the application is reachable. Confirming the presence and reachability of this technology is importan

CVE advisoryCRITICAL

CVE-2026-70306

SharePoint Cross-Site Scripting Vulnerability Allows Spoofing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A cross-site scripting vulnerability in Microsoft Office SharePoint allows an attacker to perform spoofing. This could enable an attacker to inject malicious scripts into web pages, impersonating legitimate content or actions and potentially leading to further compromise. SharePoint is commonly deployed as an internet-

CVE advisoryCRITICAL

CVE-2026-69223

Apache Allura Webhooks Vulnerable to Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache Allura's webhook functionality contains a critical Server-Side Request Forgery vulnerability. This flaw could allow an unauthenticated attacker to trick the webhooks into making unintended requests to internal or external resources, potentially leading to unauthorized access to sensitive information or internal

CVE advisoryKnown Exploit

CVE-2026-68820

Windows Ancillary Function Driver Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock allows a local attacker to elevate privileges. This could impact system integrity and permit unauthorized modifications if exploited. Applicable systems require attention to mitigate this risk.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-65791

Windows iSCSI Target Service Heap Overflow Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow in the Windows iSCSI Target Service allows an unauthorized attacker to execute code remotely over a network. This vulnerability, if reachable, could lead to system compromise and potential data loss. It is important to determine if this service is active and exposed in your environment.

CVE advisoryCRITICAL

CVE-2026-65768

Microsoft Teams for Android Path Traversal Vulnerability Allows Network Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A path traversal vulnerability in Microsoft Teams for Android could allow unauthorized remote attackers to execute code over a network. This issue arises from improper handling of file paths within the application. The primary concern is to determine if the affected technology is in use and if any network exposure exis

CVE advisoryCRITICAL

CVE-2026-62893

Windows Deployment Services Use After Free Network Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical use-after-free vulnerability in Windows Deployment Services allows an unauthenticated network attacker to execute arbitrary code. This could lead to system compromise if the service is reachable over a network. Confirming the use and exposure of this technology within your environment is advised.

CVE advisoryCRITICAL

CVE-2026-62878

Windows DNS Stack Buffer Overflow Allows Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Since Windows DNS is typically internet-facing, this vulnerability could be exploited remotely by an unauthenticated attacker, potentially leading to a significant breach. It is important to determine if this se

CVE advisoryCRITICAL

CVE-2026-62815

Microsoft QUIC Use After Free Network Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A use-after-free vulnerability in Microsoft QUIC, a network communication technology, could enable an unauthorized attacker to execute code remotely over a network. This means a flaw in memory management could potentially be exploited to gain control of code execution. Confirmation is needed to determine if environment

CVE advisoryCRITICAL

CVE-2026-59124

Microsoft HPC Pack Network Code Execution via Untrusted Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Microsoft High Performance Computing Pack has a critical deserialization vulnerability that could allow an unauthorized attacker to execute code over a network. This issue arises from improper handling of untrusted data and could impact system integrity and availability if exploited. Organizations should verify if they

CVE advisoryCRITICAL

CVE-2026-57104

Azure Storage Explorer Cross-Site Scripting Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Azure Storage Explorer has a critical vulnerability that could allow an unauthorized attacker to elevate privileges over a network. This could impact the confidentiality, integrity, and availability of managed cloud storage resources. Uncertainty remains regarding specific exploitation methods and the actual business i

CVE advisoryCRITICAL

CVE-2026-48362

ColdFusion OS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical OS command injection vulnerability exists in ColdFusion that allows unauthenticated attackers to execute arbitrary code remotely by sending specially crafted network requests. This could lead to a complete server compromise, impacting systems that host internet-accessible applications and potentially affecti

CVE advisoryKnown Exploit

CVE-2026-20349

Cisco Secure Firewall VPN Denial of Service Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in Cisco Secure Firewall devices' Remote Access SSL VPN service that could allow an unauthenticated attacker to cause a denial of service. This is due to insufficient error checking when processing HTTP requests. If reachable, an attacker could exploit this by sending a crafted request, causing t

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-73069

Twenty SQL Injection via Workspace Administrator Permissions.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Twenty open-source CRM platform where a workspace administrator with specific permissions can inject arbitrary SQL commands. This occurs when constructing a system's TS_VECTOR field, potentially leading to unauthorized access and modification of the application's database. The iss

CVE advisoryCRITICAL

CVE-2025-31114

Fooocus RCE via Unsafe JSON Metadata Processing

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Fooocus, an image generation tool, has a critical vulnerability in its web UI that could allow remote code execution if specially crafted metadata is processed. This flaw arises from the unsafe use of a function within the software. Currently, no patched versions are available, and the potential for exploitation exists

CVE advisoryCRITICAL

CVE-2026-72920

SeaweedFS IAM Service Credential Minting Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in SeaweedFS allows unauthenticated access to its identity and access management service, enabling attackers to create credentials and gain S3 administrative control. This issue arises when the filer's gRPC service is exposed without mandatory authentication. Interested parties should confirm if this te

CVE advisoryCRITICAL

CVE-2026-47702

Typebot Cleartext API Tokens Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

TypeBot stores API tokens in cleartext within its database, meaning unauthorized database access could expose these tokens. An attacker could then impersonate any user without needing passwords or multi-factor authentication. This vulnerability is relevant to the security of user accounts and data within the TypeBot pl

CVE advisoryCRITICAL

CVE-2026-17061

SIMULIA Execution Engine Remote Code Execution via Untrusted Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Deserialization of Untrusted Data vulnerability in SIMULIA Execution Engine allows unauthenticated remote code execution if the engine processes untrusted data. This could lead to system compromise and is relevant if the engine is exposed to network access.

CVE advisoryCRITICAL

CVE-2026-51584

usememos Account Takeover via SSO Identity Mismatch

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in usememos that allows remote attackers to achieve account takeover by manipulating single sign-on credentials. This occurs because the system incorrectly matches SSO identity on a controllable identifier, potentially enabling unauthorized access to sensitive data. This is relevant beca

CVE advisoryCRITICAL

CVE-2026-48056

Streambert Arbitrary Local Binary Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Streambert, a desktop video streaming application, has a vulnerability allowing a compromised renderer process to execute arbitrary local binaries. This issue impacts versions prior to 2.5.0, potentially affecting local system data and service behavior if exploited. Its relevance depends on whether this application is

CVE advisoryCRITICAL

CVE-2026-48046

Streambert Auto-Updater Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Streambert, a video streaming desktop app, has a vulnerability where an unvalidated auto-updater URL can lead to remote code execution if a compromised renderer process is triggered. This means an attacker could potentially make the main process download and run malicious binary files.

CVE advisoryCRITICAL

CVE-2026-46670

YesWiki Bazar Form-Import SQL Injection Allows Database Read

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Bazar form-import path of the YesWiki system, allowing attackers to read the entire database, including user password hashes. This issue is critical because it permits unauthorized access to sensitive data without any authentication, making it important to id

CVE advisoryCRITICAL

CVE-2026-72785

Craft CMS Incorrect Authorization Vulnerability Affects Category Structures

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability exists in Craft CMS, allowing a control-panel user with view-only category permissions to permanently modify category structures. This manipulation can alter category URLs, potentially breaking navigation menus and corrupting the site's internal linking. Confirmation of affected

CVE advisoryCRITICAL

CVE-2026-58115

SIMATIC IoT2050 Advanced Node-RED Unauthenticated Command Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in SIMATIC IoT2050 Advanced devices with Node-RED allows unauthenticated remote attackers to execute arbitrary system commands with full privileges. This is due to the Node-RED HTTP interface not enforcing authentication, which could lead to unauthorized control of operational technology system

CVE advisoryCRITICAL

CVE-2026-18972

Authenticated User Identity Spoofing Vulnerability Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker can spoof another user's identity by sending a request with a custom header, potentially leading to account takeover. This vulnerability allows a low-privilege user to impersonate administrators and gain elevated control. This is a critical concern for systems that handle user identity and adm

CVE advisoryCRITICAL

CVE-2026-72603

wg-easy OS Command Injection Vulnerability Allows Root Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability in wg-easy allows a user with client creation privileges to execute arbitrary commands as root. This is achieved by injecting malicious WireGuard directives into the client name field, which are then executed by the system. The primary concern is to identify if this technology is i

CVE advisoryCRITICAL

CVE-2026-72599

e107 SQL Injection Vulnerability Allows Arbitrary SQL Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An SQL injection vulnerability exists in e107, allowing unauthenticated remote attackers to execute arbitrary SQL commands via the news item page ID parameter. This could lead to unauthorized access, modification, or deletion of all database contents, including administrator credentials. This issue is relevant because

CVE advisoryCRITICAL

CVE-2026-72550

Friendica SQL Injection Allows Database Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An SQL injection vulnerability in Friendica allows unauthenticated remote attackers to execute arbitrary SQL statements. This could enable unauthorized reading, modification, or deletion of the entire database via the photo-view order parameter, posing a risk to data integrity and privacy.

CVE advisoryCRITICAL

CVE-2026-13737

CommServe Allowlist Bypass Vulnerability Allows Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in CommServe software allows unauthorized command execution via an allowlist bypass, affecting core Commvault components including the CommServe, Webserver, and Command Center. This issue could lead to unauthorized command execution, posing a risk to critical infrastructure management within Co

CVE advisoryCRITICAL

CVE-2026-58231

SAP Commerce Cloud Default Authentication Bypass Enables Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SAP Commerce Cloud has a critical vulnerability that allows unauthenticated attackers to execute arbitrary code by submitting specially crafted input to functions lacking sufficient validation, potentially compromising internal components and impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-10579

Picketlink Federation SAML Unsolicited Response Handler Allows Forged Assertions

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical flaw exists in Picketlink Federation SAML's unsolicited response handler, allowing unauthenticated attackers to bypass security controls by submitting forged assertions. This vulnerability could permit an attacker to impersonate any user, potentially leading to unauthorized access to sensitive information or

CVE advisoryCRITICAL

CVE-2026-13716

Crafty Controller Path Traversal Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Crafty Controller's server import and admin file upload functions allows authenticated attackers to upload files to arbitrary paths, potentially leading to remote code execution. This could impact the confidentiality, integrity, and availability of managed services.

CVE advisoryCRITICAL

CVE-2026-19425

Win Men Travel Agency Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a Travel Agency Management System, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This could lead to the unauthorized reading, modification, or deletion of database contents. Confirmation of the system's relevance and network exposure is critical for

CVE advisoryCRITICAL

CVE-2026-44758

SAP MII Command Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in SAP Manufacturing Integration and Intelligence allows a high-privilege attacker to execute arbitrary commands on the operating system due to insufficient input validation. This could severely impact the application's confidentiality, integrity, and availability, requiring confirmation of MII

CVE advisoryCRITICAL

CVE-2026-34265

SAP NetWeaver AS ABAP DIAG Protocol Memory Corruption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker can exploit memory corruption flaws in SAP NetWeaver Application Server ABAP's DIAG protocol parsing, potentially leading to sensitive information disclosure or system crashes. This impacts confidentiality, integrity, and availability.