NVD disclosure day

Published threat advisories for August 14, 2026

CVE advisoryCRITICAL

CVE-2026-73683

Laravel Socialite Facebook Provider Authentication Bypass via Replayed OIDC ID Tokens.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Laravel Socialite's Facebook provider has an authentication bypass vulnerability. Attackers can replay captured OIDC id_tokens to gain unauthorized access to user accounts because the nonce claim is not validated. This issue impacts the security of user account access.

CVE advisoryCRITICAL

CVE-2026-67365

Joomla iCagenda SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the iCagenda Joomla extension, allowing unauthenticated attackers to inject malicious SQL code. If reachable, this could compromise data integrity and availability. Confirm if the extension is in use and exposed to the internet.The provided text mentions a SQL injection vulnerability

CVE advisoryCRITICAL

CVE-2026-17186

IBM Db2 Mirror for i Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM Db2 Mirror for i is susceptible to a vulnerability that allows remote attackers to execute arbitrary CL commands due to improper input handling. This could potentially lead to unauthorized system access and data manipulation. It is important to determine if this technology is used and reachable within your environm

CVE advisoryCRITICAL

CVE-2026-17184

IBM Db2 Mirror for i Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in IBM Db2 Mirror for i that could allow an unauthenticated remote attacker to execute arbitrary code by controlling file names or paths. This could impact system data and service integrity. Readers should confirm if IBM Db2 Mirror for i is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-17182

IBM Db2 Mirror for i Authentication Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in IBM Db2 Mirror for i could allow remote attackers to bypass authentication and access or alter sensitive information. It's important to determine if this technology is in use and if it's exposed externally, as exploitation could lead to unauthorized data access.

CVE advisoryCRITICAL

CVE-2026-17181

IBM Db2 Mirror for i Path Traversal File Write Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM Db2 Mirror for i contains a path traversal vulnerability allowing remote attackers to write files to arbitrary locations. This could potentially impact system integrity and availability, though typical deployments are not internet-facing. Confirmation of network exposure and relevance to your environment is advised

CVE advisoryCRITICAL

CVE-2026-73678

MindsDB Minds Platform Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MindsDB Minds Platform is affected by a critical vulnerability allowing unauthenticated remote code execution. Attackers can exploit this by submitting crafted prompts to an unprotected API endpoint, leading to arbitrary OS command execution as the user running the application. This could expose sensitive information l

CVE advisoryCRITICAL

CVE-2026-50027

mcp-memory-service Unauthenticated API Document Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The mcp-memory-service, an AI memory layer, has a critical vulnerability where HTTP routes under `/api/documents/*` are accessible without authentication, even when API keys or OAuth are configured. This allows unauthenticated remote attackers to read, write, or delete arbitrary content in the memory store, bypassing s

CVE advisoryCRITICAL

CVE-2026-49457

Erlang QUIC and HTTP/3 TLS Handshake Certificate Verification Failure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `erlang_quic` and HTTP/3 client libraries did not authenticate servers during the TLS 1.3 handshake, allowing a network attacker to impersonate any server and compromise connection confidentiality and integrity, unless authenticated by a pre-shared key. This issue is fixed in version 1.4.4.

CVE advisoryCRITICAL

CVE-2026-19188

Haiwell IoT Cloud HMI Gateway OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in the Haiwell IoT Cloud HMI Gateway's Net Check feature, allowing unauthenticated attackers to execute arbitrary commands with root privileges. This could impact industrial control and IoT systems if the feature is network-accessible. Readers should care due to the

CVE advisoryMEDIUM

CVE-2025-7639

Authenticated Data Tampering Vulnerability in Enterprise SCADA Systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

This advisory details a critical vulnerability in Enterprise SCADA systems, where an authenticated operator with specific privileges could tamper with serialized data. If exploited, this tampering could lead to code execution with elevated system privileges during data deserialization, potentially impacting system oper

CVE advisoryCRITICAL

CVE-2026-73849

Emlog install.php allows unauthenticated configuration overwrite and administrator creation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Emlog, an open-source website builder, has a vulnerability in its install script that allows unauthenticated remote attackers to overwrite configuration files and create new administrator accounts. This could lead to unauthorized control over a website's database settings and administrative access. No fix is currently

CVE advisoryCRITICAL

CVE-2026-48528

Metacat SQL Injection via Unauthenticated API Endpoints

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Metacat data repository software contains an unauthenticated SQL injection vulnerability in its REST API endpoints that allows attackers to execute arbitrary SQL commands. This can lead to the extraction, modification, or deletion of all data within the database, including sensitive management and user information.

CVE advisoryCRITICAL

CVE-2026-19682

Security Center Command Injection Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in Security Center allows remote attackers to execute arbitrary commands with service account privileges, potentially impacting system integrity. Readers should care if this technology is in use and exposed, as it could lead to unauthorized command execution and data access. Uncertaint

CVE advisoryCRITICAL

CVE-2026-19681

Security Center File Upload Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated command injection vulnerability in Security Center's file upload processing may allow an attacker to execute arbitrary commands on the underlying operating system. This could occur when an authenticated user uploads a specially crafted file. The primary concern is to confirm if this specific functional

CVE advisoryCRITICAL

CVE-2026-19626

Tenable Security Center Report Generation Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical remote code execution vulnerability exists in Tenable Security Center's report generation. Authenticated, non-administrative users can exploit this by providing specially crafted input, leading to arbitrary code execution with service account privileges. This could impact vulnerability management data.

CVE advisoryCRITICAL

CVE-2026-19871

Roskus Prospero Flow CRM Hard-coded Credentials Allow Employee Impersonation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can exploit a critical vulnerability in the human resources component of a CRM, allowing them to impersonate any employee onboarded through the standard process by knowing only their email address, due to a fallback to a hard-coded password. This could lead to unauthorized access to s

CVE advisoryCRITICAL

CVE-2026-72836

FileBrowser Case-Insensitive Filesystem Directory Traversal.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in FileBrowser where it fails to properly check home directory ownership on case-insensitive filesystems, potentially allowing unauthorized access to user files. If user self-registration and directory creation are enabled on affected systems, attackers could exploit this by creating accounts wit

CVE advisoryCRITICAL

CVE-2026-72830

Grav API Plugin Scheduler Configuration Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a Grav API plugin allows attackers with scoped write permissions to bypass scope caps and inject arbitrary commands into scheduler configurations, potentially leading to remote code execution. This issue is relevant if the Grav API plugin is used for external integrations and is exposed to external a

CVE advisoryCRITICAL

CVE-2026-72826

Grav Plugin API Key Scope Bypass Allows Full Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the getgrav/grav-plugin-api plugin allows an attacker with a limited API key to create a new key with full administrative access by submitting an empty scope. This could enable further malicious actions, including configuration changes or remote code execution.

CVE advisoryCRITICAL

CVE-2026-72824

Grav API Plugin SSTI Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Grav API plugin allows an API key scope bypass, potentially leading to server-side template injection and remote code execution. This occurs when specific security configurations are enabled and an attacker can craft a request to trigger the vulnerability. Security-aware leaders should care becau

CVE advisoryCRITICAL

CVE-2026-72822

Grav API Key Scope Bypass Allows 2FA Disablement

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a Grav CMS API plugin allows an attacker to disable two-factor authentication on user accounts without proper authorization, potentially leading to account takeover. This occurs because the API key scope is not enforced on the disable2fa endpoint, bypassing security requirements. Readers should care

CVE advisoryCRITICAL

CVE-2026-72811

SiYuan Backlink Search SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in SiYuan's backlink search functionality. An attacker can execute arbitrary SQL commands by providing a specially crafted keyword, potentially leading to unauthorized cross-notebook data access and modification. This vulnerability is reachable via the publish surface.

CVE advisoryCRITICAL

CVE-2026-72810

SiYuan WebSocket Broadcast Publish Boundary Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the publish boundary of SiYuan note-taking software allows anonymous readers to receive unfiltered edits through WebSocket broadcast sessions, potentially exposing sensitive and password-protected documents without authentication. This issue is relevant because the publish surface is typically access

CVE advisoryCRITICAL

CVE-2026-12949

Wishlist Member Plugin Account Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in the Wishlist Member WordPress plugin allows attackers to take over any user account, including administrator accounts, by manipulating registration parameters to overwrite account details and suppress notifications. This can lead to full privilege escalation and compromise site admin