NVD disclosure day

Published threat advisories for August 12, 2026

CVE advisoryCRITICAL

CVE-2026-71193

OpenStack Designate Zone Creation Vulnerability Allows DNS Hijack and DoS

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated user can create overlapping DNS zones in OpenStack Designate, potentially hijacking other tenants' traffic or causing denial of service. Exploitation requires a specific, non-default configuration involving multiple pools and the AttributeFilter scheduler.

CVE advisoryCRITICAL

CVE-2026-49481

UpSnap OS Command Injection Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

UpSnap, a web app for network device management, has an OS command injection vulnerability. An authenticated, low-privileged user could exploit this by injecting commands into device management fields, potentially leading to arbitrary operating system command execution on the server. This could compromise the hosted se

CVE advisoryCRITICAL

CVE-2026-73519

WolfStack Authentication Bypass via Hard-coded Secret

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WolfStack contains a hard-coded authentication secret that unauthenticated remote attackers can use to bypass security controls and execute arbitrary commands as root within containers on the host system. This vulnerability could allow attackers to compromise system containers and gain unauthorized access if the manage

CVE advisoryCRITICAL

CVE-2026-73501

kin-openapi Authentication Bypass Via No-Op Function

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in kin-openapi, a Go library for handling API specifications. It can allow unauthenticated requests to bypass security checks, potentially leading to unauthorized access to protected API endpoints and sensitive data. This matters for applications using this library for API security.

CVE advisoryCRITICAL

CVE-2026-71471

acm-search-v2-rhel9 Collector ImageOverride RCE on Managed Clusters.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in acm-search-v2-rhel9 allows an attacker with administrative privileges on a hub cluster to deploy arbitrary container images, leading to remote code execution on all managed clusters. This could enable unauthorized command execution and access to sensitive information across the entire fleet. Security

CVE advisoryCRITICAL

CVE-2026-18749

VinceTrack Attachment Sharing Vulnerability Leaks Unmarked Case Material.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the VINCE platform allows case members to retrieve unshared case artifacts using their UUID, potentially leaking sensitive, unreleased coordinator materials to vendors. This occurs because authorization checks are not consistently applied to the `shared` status of attachments, meaning any case member

CVE advisoryCRITICAL

CVE-2026-10534

IBM Db2 IXF Import Parser Buffer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical buffer overflow vulnerability exists in IBM Db2's IXF IMPORT parser. If reachable, this could allow an unauthenticated attacker to execute arbitrary code, potentially leading to denial of service, data corruption, or compromise of database integrity and confidentiality. The primary concern is confirming if y

CVE advisoryCRITICAL

CVE-2024-27253

IBM DOORS Next Authentication Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated user may bypass security logic in IBM DOORS Next, potentially leading to unauthorized actions. This vulnerability could impact data integrity and access, depending on how the software is deployed and used within an organization. Confirmation of relevance and exposure is advised.

CVE advisoryCRITICAL

CVE-2026-66898

LXD Path Traversal Vulnerability in Backup Operations Allows File Access and Overwriting

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability in LXD allows a user with some access to manipulate file paths during backup operations, potentially enabling unauthorized file access or overwriting by importing a crafted backup archive. The primary concern is understanding the relevance and exposure of LXD within your specific environm

CVE advisoryCRITICAL

CVE-2026-19001

MongoDB BI Connector ODBC Driver Buffer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The MongoDB BI Connector ODBC Driver can experience memory corruption and potentially arbitrary code execution if it receives unusually long catalog, schema, or object names. This vulnerability impacts applications that use the driver to connect to MongoDB, potentially causing crashes or allowing for code execution if

CVE advisoryCRITICAL

CVE-2026-17616

IBM Security Verify Access Reverse Proxy Weak Cryptographic Validation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Certain configurations of IBM Security Verify Access and Verify Identity Access reverse proxies may not adequately validate user-supplied data cryptographically, potentially weakening security. This could allow attackers to compromise system integrity and gain unauthorized access to sensitive information.

CVE advisoryCRITICAL

CVE-2026-10543

IBM Db2 Privilege Escalation Vulnerability with Crafted Queries.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in IBM Db2 database software may allow privilege escalation through specially crafted queries. This could lead to unauthorized access and control of the database system. It is uncertain if this vulnerability is reachable or relevant in your environment.

CVE advisoryCRITICAL

CVE-2026-73414

Shescape JavaScript Library Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Shescape JavaScript library could allow an attacker to execute arbitrary commands on Windows systems. This occurs when the library fails to properly escape parentheses in arguments processed by `cmd.exe`, enabling malicious code injection. The primary concern is understanding where this library i

CVE advisoryCRITICAL

CVE-2026-73407

Budibase RestIntegration Credential Leakage Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Budibase low-code platform has a vulnerability where unauthenticated requests to a public API endpoint can expose stored credentials for REST integrations. An attacker could exploit this by sending a crafted request to an attacker-controlled host, potentially leading to unauthorized access to sensitive data. Reader

CVE advisoryCRITICAL

CVE-2026-73332

CamaleonCMS Contact Form Stored XSS

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stored cross-site scripting vulnerability in a CamaleonCMS contact form plugin allows authenticated attackers to inject malicious HTML into contact form settings. If reachable, this could lead to the theft of user cookies, forged administrative requests, and session takeover. You should care because this vulnerabilit

CVE advisoryCRITICAL

CVE-2026-73329

CamaleonCMS Stored XSS via Draft Post Title

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in CamaleonCMS, allowing authenticated low-privileged users to inject unsanitized HTML into draft post titles, potentially leading to administrator session compromise. This vulnerability enables attackers to execute arbitrary JavaScript in an administrator's browser, r

CVE advisoryCRITICAL

CVE-2026-73269

Cluster-Curator-Controller Privilege Escalation via Resource Naming

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the cluster-curator-controller allows a local user with namespace access to escalate privileges to cluster-wide control by creating a specific resource. This could grant broad permissions to access and manipulate secrets and cluster resources. The relevance and exposure of affected systems need confirmation.

CVE advisoryCRITICAL

CVE-2026-73268

MCE Cluster Curator Job Injection Leading to Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the cluster-curator-controller component allows a user with specific permissions to inject a malicious Job specification, leading to arbitrary code execution and privilege escalation. This vulnerability could enable unauthorized access to cluster-wide secrets.

CVE advisoryCRITICAL

CVE-2026-72804

SiYuan Unauthenticated Access to Protected Document Content

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SiYuan allows anonymous readers to retrieve content from password-protected documents and view the system's reference topology by exploiting unvalidated API endpoints. This could lead to unauthorized exposure of sensitive information. Confirming affected SiYuan instances and their exposure is importa

CVE advisoryCRITICAL

CVE-2026-72798

SiYuan Database Content Disclosure via renderAttributeView.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SiYuan allows anonymous readers to access sensitive data from hidden or password-protected databases through published content, bypassing intended access controls. This could expose private notes or other restricted information to unauthorized users. It is important to confirm if SiYuan is in use and

CVE advisoryCRITICAL

CVE-2026-72795

SiYuan Information Disclosure via Embedded Block Content Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan's handling of embedded block content in specific endpoints allows unauthorized access to protected documents by unauthenticated attackers. This could result in the disclosure of sensitive information from password-protected or hidden content. Verify your SiYuan deployment's reachability and data exposure.

CVE advisoryCRITICAL

CVE-2026-72794

Siyuan Session Cookie Signing Key Disclosure in Publish Mode.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan in publish mode exposes its session cookie signing key via an API endpoint, allowing unauthenticated attackers to forge session cookies. This enables them to impersonate users or gain administrative access. Confirming relevance and potential exposure is advised.

CVE advisoryCRITICAL

CVE-2026-72793

SiYuan Configuration Disclosure Allows Session Cookie Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan applications improperly expose sensitive configuration fields in an API, allowing unauthenticated users to obtain session cookie signing keys and encrypted notebook material. This can enable attackers to impersonate users and potentially gain administrator privileges.

CVE advisoryCRITICAL

CVE-2026-72789

SiYuan Publishing API Encrypted Notebooks Information Disclosure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SiYuan before v3.7.4 improperly handles publish access for encrypted notebooks, potentially making them publicly accessible. Anonymous readers may retrieve fully decrypted content from unlocked encrypted notebooks via the publish API. This could lead to the unintended disclosure of sensitive information.

CVE advisoryCRITICAL

CVE-2026-72508

RHACM Multicloud Operators Subscription ServiceAccount Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Red Hat Advanced Cluster Management's multicloud-operators-subscription component allows a privileged tenant to deploy arbitrary cluster-scoped resources, potentially leading to privilege escalation and arbitrary code execution. This issue could impact cluster control and security if the component is

CVE advisoryCRITICAL

CVE-2026-63300

LXD Instance Migration Bypass Allows Project Restriction Evasion

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unvalidated instance migration in LXD allows an authenticated attacker with instance creation permissions to bypass project-level security restrictions. This could enable unauthorized access to restricted system configurations or functionalities if an instance is moved into a restricted project without proper valida

CVE advisoryCRITICAL

CVE-2026-63299

LXD authorization bypass allows exceeding project resource limits.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authorization bypass vulnerability in LXD allows authenticated users to exceed project storage limits by manipulating volume operations. Exploitation could lead to excessive resource allocation. The relevance and exposure of this issue in your LXD deployments require confirmation.

CVE advisoryCRITICAL

CVE-2026-63298

LXD NVIDIA Configuration Injection Leads to Host Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives, potentially leading to arbitrary code execution on the host system with LXD daemon privileges. This issue should be reviewed for relevance if LXD is used with NVIDIA configurati

CVE advisoryCRITICAL

CVE-2026-63297

LXD Authorization Bypass via TOCTOU Flaw in Configuration Merging Allows Project Restriction Bypass.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authorization bypass vulnerability exists in LXD, allowing an authenticated attacker to circumvent project restrictions by exploiting a timing flaw during cross-project instance copies. This could enable the injection of disallowed high-privilege configurations into restricted projects, bypassing security controls.

CVE advisoryCRITICAL

CVE-2026-63296

LXD Instance Migration Authorization Bypass Allows High-Privilege Configuration Evasion.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration, potentially enabling the movement of instances with high-privilege configurations into restricted projects. This circumvents security controls, and its relevance depends on LXD'

CVE advisoryCRITICAL

CVE-2026-63294

LXD Root Command Execution via Malicious Archive Symlink

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in LXD allows an attacker to achieve root command execution on the host system by importing a crafted archive with a symlinked backup.yaml file, bypassing proper validation and enabling arbitrary command execution with root privileges. This could potentially compromise the integrity and availability of

CVE advisoryCRITICAL

CVE-2026-63293

LXD Arbitrary File Read Write via Symbolic Link in Image Import

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in LXD allows an attacker to read and write arbitrary files on the host system by exploiting improper validation of symbolic links within imported image archives. This could lead to significant compromise if the affected technology is reachable and relevant within your deployments.

CVE advisoryCRITICAL

CVE-2026-62420

LXD Authorization Bypass via Cross-Project Migration

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An authorization bypass vulnerability in LXD allows an authenticated user to circumvent project security restrictions during cross-project instance migrations. This could permit an attacker to introduce disallowed instance configurations into restricted projects by exploiting how the system processes internal cluster n

CVE advisoryCRITICAL

CVE-2026-17111

IBM i SQL Injection Allows Database Manipulation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM i systems have a critical SQL injection vulnerability allowing remote attackers to view, add, modify, or delete database information. This could impact data confidentiality and integrity if the systems are reachable and relevant. Organizations should verify their exposure to this threat.

CVE advisoryCRITICAL

CVE-2026-17083

IBM i Stack Buffer Overflow Vulnerability Allows Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stack-based buffer overflow in IBM i allows remote attackers to execute arbitrary code. This vulnerability can be exploited by sending crafted data to a vulnerable component, potentially impacting system confidentiality, integrity, and availability. Organizations should assess the relevance and exposure of affected I

CVE advisoryCRITICAL

CVE-2026-73300

Budibase MySQL Integration SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Budibase's MySQL integration, allowing attackers to inject and execute multiple SQL commands. This could lead to complete compromise of the associated database, including data theft or manipulation. The risk is heightened as low-code platforms like Budibase are often internet-facing.

CVE advisoryCRITICAL

CVE-2026-17218

IBM i Out-of-Bounds Write Vulnerability Enables Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An out-of-bounds write vulnerability in IBM i could allow remote attackers to execute arbitrary code. This affects system integrity and confidentiality. Readers should confirm if IBM i is used in their operations and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-16956

IBM Db2 Mirror for i Command Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM Db2 Mirror for i has a vulnerability where improper handling of OS commands could allow remote attackers to execute arbitrary commands. This is concerning because it could lead to unauthorized system control. You should care if your organization uses this technology, as it typically resides in internal environments

CVE advisoryCRITICAL

CVE-2026-16860

IBM i Code Execution via Uncontrolled Search Path

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM i systems have a critical vulnerability allowing authenticated attackers to execute arbitrary code via an uncontrolled search path element. While IBM i is typically deployed internally, making external exploitation unlikely, this flaw could allow an attacker with existing access to compromise system integrity and c

CVE advisoryCRITICAL

CVE-2026-73296

Microsoft UFO Unauthenticated Mobile Automation Control and Data Disclosure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Microsoft UFO framework allowing unauthenticated remote attackers to control connected Android devices, potentially disclosing sensitive data and modifying device state. This issue affects the framework's mobile data collection and action servers when reachable over the network. Readers sh

CVE advisoryCRITICAL

CVE-2026-18847

IBM i Navigator Spoofing Allows Remote Credential Harvesting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in IBM i allows remote, unauthenticated attackers to harvest credentials by spoofing the Navigator for i interface. This could lead to unauthorized access to system resources and sensitive data. Confirmation of exposure and business criticality is necessary to understand the risk.

CVE advisoryCRITICAL

CVE-2026-73294

Semaphore UI Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Semaphore UI's handling of repository URLs contains a critical vulnerability. An authenticated user with Project Manager or Owner privileges could execute arbitrary operating system commands on the Semaphore server. This could happen via specific API requests or scheduled polling, potentially allowing attackers to comp

CVE advisoryCRITICAL

CVE-2026-64639

Plesk Database Cloning Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Plesk's database cloning process allows low-privileged users to execute arbitrary code with database administrator privileges, potentially impacting data integrity and availability. Technical readers and security-aware leaders should confirm the presence and reachability of affected Plesk in

CVE advisoryCRITICAL

CVE-2026-73263

Prowler Kubernetes Provider Command Injection Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Prowler's Kubernetes provider could allow an authenticated attacker to execute arbitrary commands by providing a malicious Kubernetes configuration during a connection test. This could lead to compromise of the shared worker environment. This issue is important to address for those using Prowler for

CVE advisoryCRITICAL

CVE-2026-50561

Yuxi Authentication Bypass Allows Administrator Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in Yuxi's authentication mechanism allows an administrator token from one deployment to access another, granting unauthorized administrator privileges. This could lead to system takeover, including access to configurations and APIs. Ensure your Yuxi instances are appropriately secured.

CVE advisoryCRITICAL

CVE-2025-59324

CryptoPro Secure Disk Improper LUKS Validation Allows Bypassing Integrity Checks.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in CryptoPro Secure Disk that could allow file integrity checks to be bypassed if LUKS encryption is present. This could potentially lead to unauthorized access or modification of files. It is uncertain if this software is used within the environment, and if so, its configuration and exposure are

CVE advisoryCRITICAL

CVE-2025-59321

CPSD CryptoPro Secure Disk TPM PCR Policy Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in CryptoPro Secure Disk for Bitlocker's default TPM PCR policy can allow encrypted disk data to be unsealed through an unintended path or different hardware. This could lead to unauthorized access to sensitive information. Confirming the use of this technology and assessing its relevance is important.

CVE advisoryCRITICAL

CVE-2026-67285

Joomla SP Page Builder Arbitrary Local PHP File Inclusion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can include arbitrary PHP files accessible by the system, impacting web application integrity. This vulnerability affects a Joomla extension, potentially leading to serious security compromises if reachable. Confirm if this extension is in use and assess potential exposure to protect web ass

CVE advisoryCRITICAL

CVE-2025-59326

CPSD CryptoPro Secure Disk Policy Bypass via Temporary File Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in CryptoPro Secure Disk for Bitlocker where security policies are not fully enforced on temporary file systems, potentially allowing unsigned code to execute. This could impact system integrity and data confidentiality if exploited. Further information is needed to determine if this technology i

CVE advisoryCRITICAL

CVE-2026-57858

Cal.com Cal.diy Stored Cross-Site Scripting in BookingPageTagManager Analytics Tracking ID

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authenticated event owner in Cal.com Cal.diy can inject arbitrary JavaScript into public booking pages by supplying a malicious analytics tracking ID. This stored cross-site scripting vulnerability could allow attackers to steal session cookies, forge authenticated requests, or propagate the attack to other events b

CVE advisoryCRITICAL

CVE-2026-26035

FortiWeb Improper Authentication Allows Remote Administrator Login

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An Improper Authentication vulnerability in Fortinet FortiWeb may allow a remote, unauthenticated attacker to log into the management interface with random credentials. This could lead to unauthorized access and control of the web application firewall.

CVE advisoryCRITICAL

CVE-2026-67282

Joomla Fabrik Unauthenticated Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated attackers to execute arbitrary code by exploiting a frontend feature. This could lead to a full system compromise, impacting data and service behavior. Confirming the exposure of affected systems is crucial for understanding potential business impact

CVE advisoryCRITICAL

CVE-2025-41769

PROFINET Buffer Overflow Allows Unauthenticated Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow vulnerability in the PROFINET service, present in the default configuration, could allow unauthenticated remote attackers to reboot devices or execute arbitrary code. This issue impacts the availability and integrity of industrial control systems when the PROFINET service is network-accessible. Uncert

CVE advisoryCRITICAL

CVE-2026-66659

Tablesome Table Blind SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in Essekia Tablesome Table could enable an unauthenticated attacker to infer sensitive information from the database by sending crafted queries. This impacts the protection of customer and operational data, requiring confirmation of the plugin's use and assessment of potential exposure.

CVE advisoryCRITICAL

CVE-2026-18391

WooCommerce Subscriptions PHP Object Injection Leading to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can exploit a PHP Object Injection vulnerability in the WooCommerce Subscriptions WordPress plugin. This can lead to remote code execution on stores with High-Performance Order Storage enabled. This could result in a complete compromise of the affected store and its data.

CVE advisoryCRITICAL

CVE-2026-18366

Events Manager WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the Events Manager WordPress plugin allows unauthenticated users to change passwords, escalate privileges, or delete accounts by exploiting improper access control handling, potentially impacting user data and administrative control.

CVE advisoryCRITICAL

CVE-2026-16538

Wallet for WooCommerce Top-Up Value Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Wallet for WooCommerce WordPress plugin allows customers to credit their wallet with less value than the amount indicated, potentially impacting financial transactions. The plugin does not properly verify the collected amount before updating the wallet balance, which could lead to discrepancies.

CVE advisoryCRITICAL

CVE-2026-16051

wpmudev-updates Plugin Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the wpmudev-updates WordPress plugin that allows for remote code execution. An attacker who can obtain or replay a valid signed management request can install and execute arbitrary code. This could lead to a compromise of the affected WordPress site and its underlying server. It is un

CVE advisoryCRITICAL

CVE-2026-15039

Giftware WordPress Plugin Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the giftware WordPress plugin allows unauthenticated users to upload arbitrary files, including PHP code, due to insufficient file type validation. This could lead to remote code execution on affected servers, impacting website integrity and service operations. This issue is highly likely to be exter

CVE advisoryCRITICAL

CVE-2026-72526

ArgoCD multicloud-integrations Annotation Validation Flaw Allows Arbitrary Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in a multicloud-integrations component allows a tenant with application creation permissions to target arbitrary managed clusters, potentially leading to code execution or privilege escalation on those clusters.

CVE advisoryCRITICAL

CVE-2026-70398

RHACM GitOpsCluster Controller Token Redirection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Red Hat Advanced Cluster Management allows an authenticated tenant to redirect sensitive cluster bearer tokens to a controlled namespace, potentially leading to critical information disclosure and bypass of security policies. This impacts the GitOpsCluster controller within the platform.

CVE advisoryCRITICAL

CVE-2026-68431

Linux Kernel ksmbd Vulnerable to Truncated Transform Requests

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's SMB server may allow unauthenticated network access to disclose sensitive information through malformed requests. This occurs when a truncated transform packet bypasses size validation, causing the kernel to read beyond allocated memory and potentially return copied fields to the c