NVD disclosure day

Published threat advisories for August 17, 2026

CVE advisoryCRITICAL

CVE-2026-67919

Halo Plugin Installer Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Halo, an open-source content management platform, contains a vulnerability allowing remote code execution. An attacker could exploit this by triggering a plugin installation via a network request, potentially running arbitrary commands on affected systems. This could impact service integrity and availability. Further d

CVE advisoryCRITICAL

CVE-2026-42164

Mahara Text Block Vulnerability Allows Content Recall

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Mahara's text editing functionality could allow an unauthenticated attacker to recall backed-up content from other text sections. This may lead to unauthorized access and modification of sensitive information. Organizations using Mahara should confirm its presence and assess potential exposu

CVE advisoryCRITICAL

CVE-2026-42162

Mahara Artefact Access Vulnerability Through File Path Manipulation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Mahara, an e-portfolio system, has a vulnerability where manipulated file paths may grant unintended access to artefacts under specific circumstances. This could lead to unauthorized access to sensitive information. The issue is reachable via the network without authentication and has a high potential for external expo

CVE advisoryCRITICAL

CVE-2026-38165

xdocreport Velocity SSTI Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical Server-Side Template Injection vulnerability exists in the Velocity template engine configuration of xdocreport, potentially allowing attackers to execute arbitrary code through crafted expressions. This could impact system integrity and confidentiality if the affected component is exposed and processes untr

CVE advisoryCRITICAL

CVE-2026-71424

Onyx AI Platform OAuth Header Exposure Vulnerability. [cite:]

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Onyx AI platform API endpoints can expose another user's OAuth Authorization header due to a flaw in token storage, potentially allowing unauthorized access to sensitive credentials. This vulnerability, which affects Onyx prior to specific versions, can be reached via network access with limited privileges. It is impor

CVE advisoryCRITICAL

CVE-2026-67960

PbootCMS Arbitrary Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in PbootCMS allows unauthenticated attackers to execute arbitrary code via specific controller components. This could lead to unauthorized system control or data compromise, warranting attention for any organization using this web content management system. The uncertainty lies in confirming th

CVE advisoryCRITICAL

CVE-2026-67854

Qcms SQL Injection Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in Qcms may allow remote attackers to execute arbitrary code. This issue is reachable externally and could impact system confidentiality, integrity, and availability. Confirmation of Qcms deployment and its business criticality is needed to manage this risk.

CVE advisoryCRITICAL

CVE-2026-64849

MLflow Webhooks SSRF to Internal Services

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An open-source AI engineering platform has a vulnerability where an unauthenticated request to its webhook test endpoint can be redirected to internal or cloud metadata services, potentially exposing sensitive information. This issue allows an attacker to reach internal services by exploiting improper URL validation af

CVE advisoryCRITICAL

CVE-2026-51977

Trueview T18061 Camera RSA Private Key Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in a security camera that allows a physically proximate attacker to escalate privileges by accessing the RSA private key. This could lead to unauthorized control and impact the confidentiality and integrity of the system.

CVE advisoryCRITICAL

CVE-2026-42163

Mahara LTI Unauthorized Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Mahara, an e-portfolio system, allowing unauthorized access to internal accounts via Learning Tools Interoperability. This issue, affecting LTI 1.1 and 1.3 Advantage configurations, could lead to exposure or modification of user data and system behavior. Organizations using Mahara wit

CVE advisoryCRITICAL

CVE-2026-75110

MemOS Authentication Bypass Leads to Full API Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MemOS, a memory operating system for LLMs and AI agents, has a vulnerability where an unset environment variable can allow unauthenticated remote attackers to bypass access controls, granting them full administrative and data access. This occurs when authentication is enabled but the `INTERNAL_SERVICE_SECRET` is not co

CVE advisoryCRITICAL

CVE-2026-75106

OpnForm Editable Submission Secrets Exposed Via Empty Hashids Salt

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpnForm's handling of editable submission secrets is vulnerable due to a predictable hashing mechanism, potentially allowing unauthenticated attackers to access or alter submission data. This issue warrants attention as it exposes user information and the integrity of submitted content.

CVE advisoryCRITICAL

CVE-2026-67967

Tenda W20E Buffer Overflow Allows Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical buffer overflow vulnerability exists in Tenda W20E network devices, potentially allowing remote code execution by an unauthenticated attacker. This could compromise device functionality and sensitive information handled by the router. It is important to confirm if these devices are deployed within the enviro

CVE advisoryCRITICAL

CVE-2026-67966

Tenda W20E Telnet Activation Vulnerability Grants Root Shell Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Tenda W20E routers, allowing unauthenticated remote attackers to activate the Telnet service and gain root shell access. This could enable an attacker to control the router's operation if the device is reachable from the internet.

CVE advisoryCRITICAL

CVE-2026-67965

Tenda W20E Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Tneda W20E, allowing remote attackers to execute arbitrary code via the url_need_login function. This could lead to a compromise of network devices and the networks they protect. The primary concern is confirming the relevance and exposure of affected devices.

CVE advisoryCRITICAL

CVE-2026-67926

JeecgBoot AI Chat Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the JeecgBoot AI Chat Module allows unauthenticated remote attackers to execute arbitrary code via a specific file parameter. This could lead to a compromise of system integrity and confidentiality if the module is reachable. It is uncertain if this technology is in use and needs immediate a

CVE advisoryCRITICAL

CVE-2026-67917

Azuracast SQL Injection in Backup Restore Allows Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A SQL injection vulnerability exists in the backup restore functionality of zuraCast, potentially allowing a remote attacker to escalate privileges by exploiting improperly validated SQL commands within backup files. This issue could impact database integrity and administrative control if the affected function is reach

CVE advisoryCRITICAL

CVE-2026-66795

Managedcluster-import-controller CSR Validation Flaw Leads to Hub Cluster Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the managed cluster import controller allows a privileged spoke cluster service account to submit a malicious certificate signing request, potentially leading to privilege escalation and administrative access on the hub cluster. This vulnerability requires internal access to exploit.

CVE advisoryCRITICAL

CVE-2026-65974

ERPNext Server-Side Template Injection Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ERPNext allows limited authenticated users to inject server-side code by exploiting improper template rendering. This could permit remote code execution, impacting system integrity and confidentiality. Readers should care because ERPNext is a widely used ERP tool, and this flaw could lead to signific

CVE advisoryCRITICAL

CVE-2026-47698

vm2 Sandbox Escape via Prototype Chain Manipulation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the vm2 Node.js sandbox library could permit arbitrary host command execution. This arises from flaws allowing malicious code within the sandbox to manipulate host prototypes and bypass security controls. The potential for unauthorized command execution necessitates verifying if this library

CVE advisoryCRITICAL

CVE-2026-47686

vm2 Sandbox Escape Via Unsanitized Error Cause

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 Node.js sandboxing library allows specially crafted code to escape its isolated environment and execute arbitrary host commands. This occurs when an error's cause is not properly sanitized, potentially exposing powerful host objects like `process`. This could enable unauthorized access and co

CVE advisoryCRITICAL

CVE-2026-39255

SteelSeries GG macOS Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical buffer overflow vulnerability exists in SteelSeries GG software for macOS. If reachable, a remote attacker could exploit this flaw to execute arbitrary code. Further investigation is needed to confirm if this software is deployed in your environment and to understand the potential exposure.

CVE advisoryCRITICAL

CVE-2026-39254

SteelSeries GG macOS Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical buffer overflow vulnerability exists in SteelSeries GG software on macOS, potentially allowing remote attackers to execute arbitrary code. This issue is reachable over a network and does not require authentication or user interaction, posing a risk to system integrity. Confirming the presence of this softwar

CVE advisoryCRITICAL

CVE-2026-71472

Authenticated Command Injection in acm-search-v2-rhel9

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated attacker could inject malicious commands into acm-search-v2-rhel9 by exploiting improper input validation, potentially leading to arbitrary code execution within a privileged container. This vulnerability could enable system compromise if reachable.

CVE advisoryCRITICAL

CVE-2026-68004

OSSRS SRS Remote Code Execution via RTMP Publish Authorization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in OSSRS SRS, a streaming media server, could allow remote code execution. This issue, related to RTMP publish authorization and security configurations, could impact systems that handle live video traffic. Confirming the use of this technology is important for assessing potential exposure.

CVE advisoryCRITICAL

CVE-2026-67678

RainyGao-GitHub DocSys File Upload Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical file upload vulnerability in a document management system allows remote attackers to execute arbitrary code, potentially impacting system integrity and availability. Organizations should verify if this technology is in use and assess any potential exposure.

CVE advisoryCRITICAL

CVE-2026-66792

Privilege Escalation in multicloud-operators-subscription Allows Cluster Resource Deployment

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the multicloud-operators-subscription component allows a user on a managed cluster to escalate privileges by creating a crafted subscription. This could grant an attacker the ability to deploy resources into any namespace with elevated permissions, potentially leading to unauthorized access and control over c

CVE advisoryCRITICAL

CVE-2026-50775

DataHub Image Retrieval SSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A blind SSRF vulnerability in DataHub allows remote attackers to execute arbitrary code by tricking the server into retrieving an image from a crafted URL. This could lead to unauthorized actions on the server due to improper error handling. This is a concern for systems managing data access.

CVE advisoryCRITICAL

CVE-2026-50774

GAPTEQ Designer Privilege Escalation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical privilege escalation vulnerability exists in GAPTEQ Designer, potentially allowing unauthenticated remote attackers to gain elevated access via the Company Manager role. This could lead to unauthorized modification of system data and service behavior. Organizations should verify if GAPTEQ Designer is in use

CVE advisoryCRITICAL

CVE-2026-74254

Joomla Extension SQL Injection in Page Builder CK < 3.6.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the Joomla Extension Page Builder CK, allowing unauthenticated attackers to access or modify website data. This issue could impact system data integrity and service availability if the extension is deployed and reachable.

CVE advisoryCRITICAL

CVE-2026-74253

Joomla Extension Sourcerer Unauthenticated Code Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated code execution due to unverified user input processed in rendered HTML. If reachable, this could lead to arbitrary code execution, impacting website integrity and availability. Identifying the use of this extension is crucial for affected organizatio

CVE advisoryCRITICAL

CVE-2026-50772

Squirro Cognitive Search Password Reset Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can exploit a vulnerability in Squirro Cognitive Search's password reset function to execute arbitrary code. This could allow unauthorized system access and control. The primary concern is to determine if Squirro Cognitive Search is deployed and accessible within your environment.

CVE advisoryCRITICAL

CVE-2026-50770

Squirro Cognitive Search Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in Squirro Cognitive Search allows a remote attacker to escalate privileges via a crafted request, potentially granting unauthorized access to organizational data. This issue is relevant because it affects a system designed for enterprise search and data analytics, and its reachability

CVE advisoryCRITICAL

CVE-2026-71479

New API Billing Credit Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in the New API LLM gateway and AI asset management system that could allow manipulation of financial transactions. User-controlled quantities in billing calculations can overflow, potentially enabling conversion of charges into account credit and affecting upstream funds. Readers should care to c

CVE advisoryCRITICAL

CVE-2026-64859

New API LLM Gateway Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in an AI asset management system acting as an LLM gateway, potentially allowing an authenticated administrator to access root-level system configurations by obtaining the root user's access token. This could lead to unauthorized access and modification of sensitive data. It is important

CVE advisoryCRITICAL

CVE-2026-55674

Discourse Cross-Site Scripting via Crafted Cookie

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Discourse allows unauthenticated attackers to inject HTML and execute JavaScript in users' browsers by sending a crafted cookie. This could lead to arbitrary code execution when visitors view affected pages. The platform's public-facing nature increases the potential for exploitation.

CVE advisoryCRITICAL

CVE-2026-71566

FakeFish Arbitrary VM Control via KubeVirt Misconfiguration.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in FakeFish allows cluster users to control virtual machines by exploiting how credentials are handled and KubeVirt relies on a KUBECONFIG file. This could lead to unauthorized VM power state changes and the mounting of arbitrary CD images. The exposure is classified as external, though its specific rea

CVE advisoryCRITICAL

CVE-2026-14564

Logsign SIEM Credential Exposure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Logsign SIEM could allow an authenticated attacker to retrieve embedded sensitive data due to insufficiently protected credentials. This is significant because SIEM systems are critical for security monitoring and an attacker gaining access to embedded sensitive data could lead to further malicious a

CVE advisoryCRITICAL

CVE-2026-74843

Wavlink Export Pingortrace CGI Stack Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Wavlink devices allows remote attackers to cause a stack-based buffer overflow via crafted HTTP requests to the Export Pingortrace CGI. This could lead to unauthorized control of the device. The exploit is publicly disclosed and potentially exploitable.

CVE advisoryCRITICAL

CVE-2026-74901

Openssl_encrypt Authentication Bypass via AES-CTR Fallback

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in a cryptographic library allows attackers to bypass authentication by modifying ciphertext in transit, leading to undetected data alteration. This occurs when AES-GCM decryption failures trigger a fallback to unauthenticated AES-CTR mode. It's uncertain if this library is exposed externally, but the potential

CVE advisoryCRITICAL

CVE-2026-74900

openssl_encrypt PQc Decapsulation Fallback Deterministic Shared Secret Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical flaw in `openssl_encrypt` allows attackers with minimal private key data to derive shared secrets, potentially decrypting all encrypted data due to a silent fallback in KEM decapsulation. Organizations should confirm if this crypto library is in use, as a fallback risk could lead to data compromise.

CVE advisoryCRITICAL

CVE-2026-74899

OpenSSL Encrypt Sandbox Escape Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A sandbox escape vulnerability in a component that executes code in a restricted environment allows attackers to access system functions and execute arbitrary commands by exposing Python type objects. This could lead to unauthorized operating system command execution if the affected technology is reachable. The relevan

CVE advisoryCRITICAL

CVE-2026-74896

openssl_encrypt Sandbox Escape via Dunder Attribute Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in a library's code analysis component that could allow attackers to execute arbitrary system commands from plugin code by bypassing security restrictions through dunder attribute traversal techniques. This issue is a concern if the vulnerable component is reachable and re

CVE advisoryCRITICAL

CVE-2026-74895

OpenSSL Encrypt Plugin Sandbox Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the openssl_encrypt library that allows attackers to bypass sandbox restrictions during plugin execution. This could enable malicious plugins to gain unrestricted access to the filesystem, network, and subprocesses, potentially leading to system compromise. It is important to assess t

CVE advisoryCRITICAL

CVE-2026-74894

OpenSSL Encrypt Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the `verify_api_token` function of `openssl_encrypt` allows for authentication bypass by accepting any non-empty Bearer token, potentially enabling attackers to upload, enumerate, and revoke keys without authorization. This bypass, triggered by a simple API request, could allow unauthorized access an

CVE advisoryCRITICAL

CVE-2026-74890

openssl_encrypt Authentication Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in openssl_encrypt that can bypass data integrity checks if an attacker can execute code and set a specific environment variable. This bypass prevents HMAC tag generation and verification, potentially allowing unauthenticated ciphertext to be accepted as legitimate encrypted data. Readers should

CVE advisoryCRITICAL

CVE-2026-74889

OpenSSL Encrypt Weak Key Derivation via HKDF Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in `openssl_encrypt` related to key derivation using HKDF without a salt. This weakness can lead to predictable key generation, potentially weakening cryptographic security and enabling multi-target attacks. While the risk is considered very unlikely due to its library-level nature, its relevance

CVE advisoryCRITICAL

CVE-2026-74887

Openssl Encrypt Insecure Random Import Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Python encryption library unintentionally imports a non-cryptographic random number generator, posing a risk of predictable values if future code inadvertently uses this weaker source. While current cryptographic operations are unaffected, the import creates a potential hazard.

CVE advisoryCRITICAL

CVE-2026-74886

OpenSSL Encrypt Plugin Sandbox Bypass Leads to Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A sandbox bypass vulnerability in `openssl_encrypt` allows attackers to import and execute dangerous modules, potentially leading to arbitrary code execution through string obfuscation or encoding. The reachability of this vulnerability depends on how the affected library is implemented within an organization's systems

CVE advisoryCRITICAL

CVE-2026-74880

OpenSSL Encrypt Token Leakage Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in `openssl_encrypt` where refresh tokens can be exposed via URL query parameters in keyserver and telemetry routes. This exposure in server logs or HTTP headers could allow attackers to gain unauthorized access to systems. Confirming the use of this function in relevant routes is necessary to un

CVE advisoryCRITICAL

CVE-2026-74878

openssl_encrypt TOTP Rate Limiter Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in a time-based one-time password (TOTP) implementation where an in-memory rate limiter is not shared across server workers and resets on restart. This allows attackers to bypass authentication rate limiting by distributing attempts across instances or retrying after a server restart, potentially

CVE advisoryCRITICAL

CVE-2026-74876

openssl_encrypt Unverified Key Bundle Encryption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the `openssl_encrypt` library allows attackers to create unverified key bundles from untrusted data. If reachable, this could enable attackers to encrypt secrets using attacker-controlled public keys, leading to data leakage. This issue warrants attention due to the potential for unauthorized access

CVE advisoryCRITICAL

CVE-2026-74875

openssl_encrypt Bypass Schema Validation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The openssl_encrypt library may accept malformed data by skipping JSON schema validation if the jsonschema library is not installed, potentially allowing malicious data processing. Reachability depends on application implementation and attacker influence over metadata. Confirming its use and exposure within our environ

CVE advisoryCRITICAL

CVE-2026-74872

OpenSSL Encrypt Whirlpool Hash Arbitrary Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Whirlpool hash implementation of `openssl_encrypt` that permits arbitrary code execution. Attackers may be able to run malicious native code by placing specially crafted files in directories that the software uses to load modules without verifying their integrity.

CVE advisoryCRITICAL

CVE-2026-74800

SiYuan Stored Cross-Site Scripting via Asset Upload

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

SiYuan software has a vulnerability that allows authenticated attackers to upload HTML files as assets, which can then lead to stored cross-site scripting attacks. When a workspace owner opens such an asset, malicious scripts could execute with full kernel API access. This issue is relevant if SiYuan is in use and this

CVE advisoryCRITICAL

CVE-2026-74798

SiYuan Kernel Path Traversal Arbitrary File Read and Deletion via Database Clean Tool

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability exists in the SiYuan kernel's database cleaning tool, allowing an authenticated user to read and delete arbitrary files. This occurs because the tool does not adequately validate an `id` parameter, enabling an attacker to manipulate file paths and access unintended system files.

CVE advisoryCRITICAL

CVE-2026-15623

Google Cloud SecOps SQL Injection in Dashboard Widget API

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in a legacy dashboard widget API for Google Cloud's security operations platform may allow an authenticated attacker to execute unauthorized database queries. While a fix has been released and no customer action is required, this highlights potential risks in older API functionalities.

CVE advisoryCRITICAL

CVE-2026-19977

EFM ipTIME A3004T Session Validation Improper Authentication Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in EFM ipTIME A3004T's session validation, allowing remote, unauthenticated manipulation of the HTTP interface. Exploitation is possible, and public exploits may be in use, potentially leading to device compromise. The vendor has not responded to disclosure.