NVD disclosure day

Published threat advisories for August 13, 2026

CVE advisoryCRITICAL

CVE-2026-73665

FreePBX UCP Node Arbitrary Command Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in FreePBX's User Control Panel (UCP) Node server, allowing unauthenticated attackers to execute arbitrary commands. This is possible by connecting to custom namespaces that bypass authentication and sending crafted data, potentially compromising system integrity and availability.

CVE advisoryCRITICAL

CVE-2026-73663

FreePBX Missed Call Module SQL Injection Leading to Administrator Account Compromise.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the FreePBX missedcall module, allowing unauthenticated attackers to inject SQL via crafted SIP headers when a monitored extension goes unanswered. This could corrupt the database, alter administrator accounts, and grant unauthorized remote access. Organizations using FreePBX should c

CVE advisoryCRITICAL

CVE-2026-73421

NextAuth.js Configuration Error Allows Unauthorized Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A configuration error in NextAuth.js can allow unauthenticated access to protected routes. If a Next.js application using this library experiences certain server configuration issues, access checks may fail open, granting unauthorized users access. This impacts applications where access is gated solely by checking for

CVE advisoryCRITICAL

CVE-2026-73420

NextAuth.js Email Link Misdirection Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

NextAuth.js authentication can be exploited if a specially crafted Unicode character in an email address causes passwordless sign-in links to be misrouted to an attacker. This could allow an attacker to take over a victim's account. Applications are affected if they use the default email normalizer and a downstream mai

CVE advisoryCRITICAL

CVE-2026-73302

Budibase OIDC Account Linking Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Budibase low-code platform allows an attacker to merge their identity with a victim's account by using an unverified email from a configured identity provider, potentially inheriting the victim's roles and permissions. This could grant unauthorized access within the Budibase environment.

CVE advisoryCRITICAL

CVE-2026-72851

Budibase Unauthenticated Webhook SQL Injection.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Budibase webhook-triggered automations. Attackers can exploit this by sending crafted JSON to a webhook endpoint, injecting SQL payloads that execute with database credentials. This could lead to unauthorized data exfiltration, modification, or persistence in con

CVE advisoryCRITICAL

CVE-2026-72850

Budibase Arbitrary File Write via Path Traversal

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Budibase fails to properly sanitize S3 object keys, allowing authenticated users to write arbitrary content to any location on the server during workspace exports. This vulnerability could lead to system compromise if an attacker can exploit it. Security-aware leaders should confirm if their organization uses this plat

CVE advisoryCRITICAL

CVE-2026-72842

LuCI LXC Container Management Authorization Bypass Leads to Host Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical authorization bypass vulnerability in OpenWrt's luci-app-lxc allows low-privileged users to execute arbitrary code on the host system. This occurs when attackers use path traversal to escape container directories and control host scripts, granting them root privileges. The issue is relevant if the affected a

CVE advisoryCRITICAL

CVE-2026-72841

luci-app-openvpn Path Traversal and Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The luci-app-openvpn component has a path traversal vulnerability allowing authenticated users to write arbitrary files, potentially leading to persistent root code execution. This could result in unauthorized system compromise if the affected functionality is reachable.

CVE advisoryCRITICAL

CVE-2026-72839

Filebrowser Unrestricted File Access via Self-Signup Privilege Escalation.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated Filebrowser vulnerability allows attackers to register accounts with full server file access if self-signup is enabled with default settings. This could lead to unrestricted access to all files on the server. Assess Filebrowser deployments for enabled self-signup and review permissions to mitigate th

CVE advisoryCRITICAL

CVE-2026-72776

AgenticSeek Unauthenticated Remote Code Execution via Query API

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in AgenticSeek permits unauthenticated network attackers to run arbitrary commands by sending crafted queries to an unprotected API, potentially leading to full host compromise. This matters for systems processing external queries, requiring confirmation of relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-8715

Vault Secrets Operator Arbitrary File Read and Credential Exfiltration

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Vault Secrets Operator allows a limited-permission tenant to read files from the operator pod and exfiltrate credentials, potentially enabling privilege escalation within the Kubernetes cluster. This issue is relevant for technical readers and security-aware leaders to understand potential internal t

CVE advisoryCRITICAL

CVE-2026-19297

IBM Langflow OSS Improper Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS contains an authentication vulnerability that could allow unauthorized remote access to user accounts by repeatedly attempting logins. This issue, stemming from improper restriction of excessive authentication attempts, may enable attackers to bypass security measures. Organizations should confirm if t

CVE advisoryCRITICAL

CVE-2026-18249

IBM i Improper Pointer Validation Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in IBM i systems allows authenticated attackers to elevate privileges by improperly validating pointers from Java-controlled addresses, potentially impacting confidentiality, integrity, and availability. While exploitation requires authenticated access, the reachability of these systems is uncertain.

CVE advisoryCRITICAL

CVE-2026-17481

IBM Documentation Offline Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

IBM Documentation Offline contains a critical vulnerability where improper log neutralization can allow remote attackers to execute arbitrary code. While the product is designed for offline use, making remote exploitation unlikely, organizations should confirm if it is deployed in a way that could expose it to such thr

CVE advisoryCRITICAL

CVE-2026-17101

IBM i Improper Authentication Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM i systems contain an improper authentication vulnerability that could allow remote attackers to execute arbitrary code or access sensitive information. This could impact system integrity and data confidentiality. It is uncertain if this vulnerability is reachable or relevant to your environment.

CVE advisoryCRITICAL

CVE-2026-73656

Trigger.dev Worker Linking Vulnerability Allows Deployment Hijacking

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Trigger.dev platform allows an authenticated user to link an unauthorized background worker to a victim deployment. This could enable manipulation of the victim deployment's status. The platform is used for building and deploying AI agents and workflows.

CVE advisoryCRITICAL

CVE-2026-17206

IBM i Buffer Overflow Allows Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical buffer overflow vulnerability exists in IBM i, potentially allowing remote attackers to execute arbitrary code. This could impact system data and services, posing a risk to confidentiality, integrity, and availability. Understanding the relevance and exposure of affected IBM i systems is important.

CVE advisoryCRITICAL

CVE-2026-16867

IBM i Improper Authentication Allows Resource Access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM i systems are susceptible to improper authentication during NTLM session negotiation, allowing a remote attacker to access server resources with authenticated user privileges. This vulnerability is relevant if these systems are reachable over a network and utilize NTLM for authentication, potentially leading to una

CVE advisoryCRITICAL

CVE-2026-16815

IBM i Stack Buffer Overflow Allows Denial of Service and Information Disclosure

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack-based buffer overflow in IBM i systems can permit remote attackers to cause a denial of service and potentially obtain sensitive information. While the vulnerability is network-reachable, IBM i systems are typically deployed internally, making external exploitation unlikely.

CVE advisoryCRITICAL

CVE-2026-14525

IBM WebSphere Liberty Authentication Bypass via RTComm Features

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass if the rtcomm-1.0 or rtcommGateway-1.0 features are enabled. This could allow unauthenticated access to services, potentially impacting data confidentiality, integrity, and availability. The risk is heightened as these features are often

CVE advisoryCRITICAL

CVE-2026-73653

Vitest Browser Mode Local File Access Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Vitest testing framework's Browser Mode API allows unauthenticated access to local files, enabling arbitrary file reads, overwrites, or deletions. This could impact the confidentiality and integrity of data within the Vitest process if the API is reachable. Readers should care about this issue as

CVE advisoryCRITICAL

CVE-2026-17197

IBM i Security Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM i systems are vulnerable to unauthorized access and potential system control due to improper validation of client-asserted identity. This could allow a remote attacker to bypass security restrictions, posing a risk to system data and services. Readers should care to confirm if their IBM i systems are exposed to ext

CVE advisoryCRITICAL

CVE-2026-73649

Velocity.js Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Velocity.js, a JavaScript template engine, where unfiltered property-read expressions can allow attackers to execute arbitrary commands, access sensitive data, and gain network access. This occurs when vulnerable applications process attacker-controlled templates. It is important to i

CVE advisoryCRITICAL

CVE-2026-73644

OpenDJ Improper Authorization Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenDJ, a directory service, has a vulnerability that could allow an authenticated user with specific privileges to impersonate other users. This may lead to unauthorized access to directory service data. It is important to confirm if OpenDJ is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-73567

sm-crypto SM2 Private Key Recovery and Signature Forgery Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the sm-crypto JavaScript library allows attackers to reconstruct SM2 private keys and forge signatures by observing random number generation outputs and estimating key generation time. This affects systems using the library for secure communication and data integrity. The issue is fixed in version 0.5.0.

CVE advisoryCRITICAL

CVE-2026-67614

CyberPanel WebTerminal Unauthenticated Root Shell Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A hard-coded secret in CyberPanel's WebTerminal service enables unauthenticated remote attackers to forge authentication tokens and gain root shell access via WebSocket on port 8888. This allows for unauthenticated remote network access and potential server compromise. Technical readers and security-aware leaders shoul

CVE advisoryCRITICAL

CVE-2026-58508

Gitea Migration and Mirroring SSRF Vulnerabilities

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Two Server-Side Request Forgery (SSRF) vulnerabilities exist in Gitea's migration and mirroring features. These flaws could allow an attacker to trick Gitea into making requests to arbitrary internal or external resources, potentially leading to unauthorized access or data exposure. The primary concern is confirming if

CVE advisoryCRITICAL

CVE-2026-58443

Gitea Repository Tokens Allow Unauthorized Private Branch Updates.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a repository management platform allows public tokens to update private branches. This could enable unauthorized code modification, potentially impacting code integrity and project control. Confirming relevance and assessing exposure is crucial to understanding organizational implications.

CVE advisoryCRITICAL

CVE-2026-58433

Gitea Team Repository Linking Endpoint Bypass Allows Unauthorized Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a Git platform's team-repository linking endpoint bypasses administrator settings, potentially allowing unauthorized linking of repositories to teams. This could lead to unauthorized access or modification of sensitive code repositories and organization data. The reachability of such platforms, often

CVE advisoryCRITICAL

CVE-2026-56750

Gitea Remember-Me Token Theft Allows Attacker Session Hijacking

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A security vulnerability in Gitea's session management could allow an attacker to steal a user's "remember-me" token, potentially leading to unauthorized account access and control without valid credentials. This could expose stored data and enable actions on behalf of the compromised user.

CVE advisoryCRITICAL

CVE-2026-56654

Gitea Privilege Escalation via Access Token Scope Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in API access token scope management allows unauthenticated attackers to escalate privileges, potentially granting unauthorized access to sensitive data and system control. It is important to determine if the affected technology is in use and assess any exposure to understand potential risks to

CVE advisoryCRITICAL

CVE-2026-56443

Token Scope Bypass Affects Limited-Visibility Owners

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A security vulnerability exists in a widely used Git platform that affects access controls for limited-visibility owners of repositories and packages. This bypass of token scopes could allow unauthorized access and modification of sensitive data within Gitea instances. The potential impact on data integrity and availab

CVE advisoryCRITICAL

CVE-2026-55982

OIDC Userinfo Endpoint Mishandles Identity Claims Without Scope Enforcement

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in OpenID Connect userinfo endpoints where identity claims can be returned without enforcing API token scopes. This could allow unauthenticated access to sensitive user information. Confirmation of affected systems and their exposure is necessary.

CVE advisoryCRITICAL

CVE-2026-13051

Form Processor HtmlArea Method Dispatch and Resource Exhaustion Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a Perl HTML processing library allows for method dispatch and resource exhaustion via crafted HTML. This could lead to unhandled exceptions or excessive memory allocation when processing user-submitted markup, impacting application availability.

CVE advisoryCRITICAL

CVE-2022-4993

HTML::FormHandler Input Handling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in HTML::FormHandler for Perl could allow an attacker to execute arbitrary code or cause resource exhaustion by sending specially crafted input. This occurs when error messages, influenced by request data, are improperly processed as templates. The impact depends on whether the affected library is used

CVE advisoryKnown Exploit

CVE-2026-73570

Zimbra Collaboration OS Command Injection Vulnerability via SNMP Notifications.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability exists in Zimbra Collaboration when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker could exploit this by sending specially crafted SMTP requests to execute arbitrary commands on the server, potentially impacting data in

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-73533

Ninja Tables Pro Backdoor via Tampered Plugin Build

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a popular WordPress plugin due to a compromised build served from a decommissioned server, allowing for malicious code insertion. This can lead to a backdoor, persistent files, and a passwordless administrator account, potentially compromising website integrity and backend services.

CVE advisoryCRITICAL

CVE-2026-73532

Fluent Forms Pro Malicious Code Backdoor via Tampered Build

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WordPress plugin allows attackers to embed malicious code through a compromised plugin build, creating a backdoor that enables unauthorized access and persistent control. This could lead to the installation of administrator accounts and scheduled tasks that survive plugin removal.

CVE advisoryCRITICAL

CVE-2026-70460

Rsync Path Traversal via Symlinks in Partial or Backup Directories

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A path traversal vulnerability in rsync allows a malicious sender to write files to arbitrary locations outside the module root by exploiting symlinks, potentially impacting system integrity. This risk is relevant if rsync is exposed to untrusted inputs and configured with specific options. <hr> The rsync vulnerability

CVE advisoryCRITICAL

CVE-2026-53793

Rsync Path Confinement Bypass Vulnerability in Chroot Mode

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An rsync path confinement bypass vulnerability exists, potentially allowing remote attackers to read or write files outside their intended scope. This occurs when rsync is configured with module roots containing a "/./" boundary marker, which attackers can exploit by crafting special paths to escape confinement. This p

CVE advisoryCRITICAL

CVE-2026-53791

Rsync Daemon IP Spoofing Vulnerability via Crafted Proxy Protocol Header

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the rsync daemon allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. This could lead to unauthorized access to systems where the rsync daemon is exposed and relies on IP rules.

CVE advisoryCRITICAL

CVE-2026-53790

Rsync Command and Argument Injection Vulnerabilities

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Rsync contains command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input. These vulnerabilities are reachable through network exposure, without requiring authentication or user interaction. This could impact systems using rsync for data transfer or sy

CVE advisoryCRITICAL

CVE-2026-66691

Nokri Theme Broken Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated broken access control vulnerability exists in the Nokri WordPress theme. This flaw may allow attackers to gain unauthorized access to system functions or sensitive data, potentially leading to a full website compromise. It is important to identify if this theme is in use to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-66478

Church Admin SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Church Admin, potentially allowing attackers to access or modify sensitive database information. This issue is externally reachable and relevant to organizations using the affected software. The actual impact depends on the database configuration and user privile

CVE advisoryCRITICAL

CVE-2026-66472

Everest Backup Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in Everest Backup software, exploitable by unauthenticated users over a network, could lead to unauthorized access to sensitive data. This external threat requires immediate attention to identify its presence and assess potential business impact.

CVE advisoryCRITICAL

CVE-2026-66465

Cartify Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated broken authentication vulnerability exists in the Cartify WooCommerce WordPress theme. This could allow attackers to take over user accounts on e-commerce sites using the theme, potentially impacting business operations and customer data. Confirming the theme's presence and reachability is im

CVE advisoryCRITICAL

CVE-2026-66458

RealPress Unauthenticated SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in RealPress could allow attackers to access or modify database information. This issue is reachable via network requests without authentication, posing a risk to data integrity and system availability if the technology is deployed and exposed.

CVE advisoryCRITICAL

CVE-2026-66453

Salon Booking System Unauthenticated Broken Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical broken authentication vulnerability exists in Salon booking systems. This flaw could allow unauthenticated attackers to gain unauthorized access, potentially leading to the manipulation of appointments or the exposure of sensitive customer data. Confirming the presence and relevance of these systems within o

CVE advisoryCRITICAL

CVE-2026-66446

If-So Dynamic Content Personalization SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the If-So Dynamic Content Personalization plugin. If reachable, an attacker could potentially access sensitive database information. This could impact the integrity of personalized user experiences and website functionality.

CVE advisoryCRITICAL

CVE-2026-66436

Active Products Tables for WooCommerce SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Active Products Tables for WooCommerce. This could allow attackers to access sensitive database information. The issue impacts public-facing online stores, making it a critical concern for e-commerce platforms.

CVE advisoryCRITICAL

CVE-2026-66424

Unauthenticated Privilege Escalation in SMS Alert Order Notifications Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the SMS Alert Order Notifications plugin, potentially allowing attackers to gain unauthorized system control. This issue is concerning because it can be exploited remotely without authentication. Confirming the plugin's presence and reachability within you

CVE advisoryCRITICAL

CVE-2026-61969

Listdom Unauthenticated SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Listdom, a WordPress plugin for directory sites, allowing unauthenticated SQL injection. This could expose sensitive database information if the plugin is publicly accessible. Confirming its use and external reachability is crucial.

CVE advisoryCRITICAL

CVE-2026-61966

WPJAM Basic Subscriber SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the WPJAM Basic plugin, allowing unauthenticated attackers to potentially access sensitive subscriber data over the network. This could impact organizations using the plugin, necessitating confirmation of its presence and potential exposure.

CVE advisoryCRITICAL

CVE-2026-61962

WP Base Booking Arbitrary Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated arbitrary code execution vulnerability exists in a WordPress booking plugin, allowing attackers to run any commands on a vulnerable server. This could lead to a full compromise of public-facing websites when the plugin is reachable over the network, highlighting the need to confirm its presence and e

CVE advisoryCRITICAL

CVE-2026-28185

Login with Google Plugin Broken Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical broken authentication vulnerability exists in the "Log in with Google" plugin. This flaw allows unauthenticated attackers to bypass login controls, potentially leading to unauthorized access to user accounts and system functions. Organizations using this plugin should identify instances, assess exposure, and

CVE advisoryCRITICAL

CVE-2026-28149

Headless Single Sign-On PHP Object Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical PHP Object Injection vulnerability exists in Headless Single Sign On, allowing unauthenticated attackers to potentially gain unauthorized system control. This issue is concerning because it could lead to arbitrary code execution and impact system integrity and availability if the software is used.

CVE advisoryCRITICAL

CVE-2026-28148

Headless Single Sign On Unauthenticated Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Headless Single Sign-On allows unauthenticated attackers to bypass security controls. This could lead to unauthorized access to sensitive information or system configurations, as Single Sign-On systems manage user authentication for multiple services.

CVE advisoryCRITICAL

CVE-2026-28142

Web Directory Free Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a web directory plugin, potentially allowing unauthorized access to sensitive data. This issue is externally exposed and could impact system data and service integrity. Confirming the plugin's usage and associated data exposure is crucial for assessing business i

CVE advisoryCRITICAL

CVE-2026-28008

OAuth SSO Client Plugin Broken Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated broken authentication vulnerability exists in an OAuth Single Sign-On client plugin that could permit unauthorized access. This issue may impact system authentication and data confidentiality, integrity, and availability. Confirmation of its use within your environment is recommended to assess potent

CVE advisoryCRITICAL

CVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WP Directory Kit plugin, potentially allowing attackers to access sensitive database information or disrupt site availability. This issue could affect websites using the plugin, impacting data integrity and service availability.

CVE advisoryCRITICAL

CVE-2026-27544

QA Analytics Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated remote code execution vulnerability exists in QA Analytics. Attackers could exploit this by sending a crafted network request to run unauthorized commands on affected systems. This is a concern if QA Analytics is in use and accessible externally, potentially leading to system compromise.

CVE advisoryCRITICAL

CVE-2026-49827

WebErpMesv2 Unauthenticated Remote Code Execution via Arbitrary File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WebErpMesv2, an industrial resource management system, contains a vulnerability allowing unauthenticated remote code execution. Attackers can upload arbitrary PHP files, potentially leading to unauthorized system control. This is significant because such systems manage critical industrial operations.

CVE advisoryCRITICAL

CVE-2026-73602

Flowise Sandbox Escape via vm2 Vulnerability Allows Arbitrary Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Flowise contains a sandbox escape vulnerability that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. This could impact system integrity and availability by enabling unauthorized code execution. Flowise instances should be identified and assessed for exposure and criti

CVE advisoryCRITICAL

CVE-2026-73601

Flowise Remote Code Execution via Custom MCP Node

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability exists in Flowise's Custom MCP node, allowing authenticated users to run arbitrary commands by manipulating specific configurations. This could lead to unauthorized system access and control. Confirming Flowise usage and exposure is crucial for understanding its relevance.

CVE advisoryCRITICAL

CVE-2026-73487

Flowise Agent Nodes Prompt Injection Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Flowise allows unauthenticated attackers to inject malicious code through AI agent nodes, potentially leading to data exfiltration, server-side request forgery, or code execution. This is a concern if Flowise is in use and exposed externally, as it could impact system data and services.

CVE advisoryCRITICAL

CVE-2026-73486

Flowise CSV Agent Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability in Flowise's CSV Agent allows authenticated attackers to execute arbitrary Python code by bypassing input validation, potentially granting them system access. This could impact systems building LLM applications. The primary concern is confirming if this technology is in use and assessing

CVE advisoryCRITICAL

CVE-2026-73485

Flowise Airtable Agent Code Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability exists in Flowise's Airtable Agent node, allowing unauthenticated attackers to execute arbitrary Python code by bypassing validation with obfuscation. This could lead to compromise of the host operating system, with potential risk to system data. It is uncertain if this affects specific p

CVE advisoryCRITICAL

CVE-2026-73483

Flowise Sandbox Escape via Puppeteer Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical sandbox escape vulnerability exists in Flowise, allowing authenticated users to execute arbitrary OS commands and disclose host files by manipulating parameters for launching external processes. This bypasses the intended JavaScript sandbox, potentially granting unauthorized access and control over the host

CVE advisoryCRITICAL

CVE-2026-59507

Hard-coded Credentials and Improper Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists due to hard-coded credentials and improper access control, potentially enabling unauthorized access to sensitive information if the affected technology is reachable. This could lead to exposure of system or user data, necessitating an assessment of its deployment and criticality within t

CVE advisoryCRITICAL

CVE-2026-59506

Missing Authentication for Critical Function CVE-2026-59506.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical function may not authenticate users, potentially allowing unauthorized network access. The specific impact depends on the affected function and system configuration, but could lead to unauthorized data access or modification. Readers should investigate their environments for potential exposure.

CVE advisoryCRITICAL

CVE-2026-59503

Sensitive and Private Information Exposure Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

This critical vulnerability allows unauthorized access to sensitive and private information via network requests without authentication or user interaction. The specific affected technology is not yet identified, creating uncertainty about its relevance and exposure within the environment, but it presents a significant

CVE advisoryCRITICAL

CVE-2026-15413

Link Factory WordPress Plugin Backdoor via Unauthenticated REST API

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical backdoor vulnerability exists in the Link Factory WordPress plugin, exposing a hardcoded, operator-controlled REST API. This allows for unauthenticated remote access, potentially leading to unauthorized data exposure or service disruption if reachable. Readers should verify if this plugin is in use within th

CVE advisoryCRITICAL

CVE-2026-14182

WooCommerce Email Verification Account Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WooCommerce WordPress plugin allows unauthenticated users to take over accounts if a user hasn't confirmed their email. Attackers can exploit a loose code comparison to verify and control any registered user's account. This could impact customer account integrity and e-commerce operations.

CVE advisoryCRITICAL

CVE-2026-49819

UpSnap Superuser Registration and RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in UpSnap allows unauthenticated attackers to register as a superuser and execute arbitrary commands, leading to potential system compromise. This issue is reachable via a network-adjacent, unauthenticated API call. Readers should care because it enables full system control if the vulnerable ap

CVE advisoryCRITICAL

CVE-2026-16770

PDF::WebKit Argument Injection via Meta Tags

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The PDF::WebKit library is vulnerable to argument injection through meta tags in HTML documents. This allows an attacker to inject commands into the PDF conversion process, potentially leading to the disclosure of local files or arbitrary file writes. This is a concern for applications that process untrusted HTML to ge