NVD disclosure day

Published threat advisories for August 18, 2026

CVE advisoryCRITICAL

CVE-2026-21580

Confluence Data Center and Server Vulnerabilities Allow Stored XSS Privilege Escalation and Security Misconfiguration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Confluence Data Center and Server allows unauthenticated attackers to execute malicious code and gain elevated privileges by exploiting security misconfigurations. This could lead to unauthorized system access and the compromise of user sessions. It is important to confirm if your deployment

CVE advisoryCRITICAL

CVE-2026-76036

Chrome for Android Dawn Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical buffer overflow vulnerability in Google Chrome on Android's Dawn component allows remote attackers to execute arbitrary code by luring users to a malicious webpage. This could impact devices if they use the affected browser technology, necessitating verification of organizational exposure.

CVE advisoryCRITICAL

CVE-2026-73930

Helidon Imperative Web Server Vulnerability Allows Unauthorized Data Access and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Fusion Middleware's Helidon product, specifically within its Imperative Web Server. This flaw allows unauthenticated attackers with network access to potentially compromise the server, leading to unauthorized data modification or deletion, unauthorized data reading, and partial

CVE advisoryCRITICAL

CVE-2026-73924

Oracle Helidon Imperative Web Server Vulnerability Leads to Data Compromise

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Helidon's Imperative Web Server allows unauthenticated attackers network access to compromise the system. Successful exploitation could lead to unauthorized modification or access to critical data. This warrants attention due to the potential for significant data compromise.

CVE advisoryCRITICAL

CVE-2026-73922

Helidon Imperative Web Server Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Helidon's Imperative Web Server allows unauthenticated network attackers to access or modify critical data. This issue requires confirmation of Helidon usage and assessment of potential data exposure within the environment.

CVE advisoryCRITICAL

CVE-2026-73921

Helidon Imperative Web Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Helidon Imperative Web Server component of Oracle Fusion Middleware that could allow an unauthenticated attacker with network access to take over the system. This issue poses a risk to confidentiality, integrity, and availability due to its high severity score. It is important to

CVE advisoryCRITICAL

CVE-2026-73920

Helidon Imperative Web Server Unauthorized Data Access and Denial of Service Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Helidon's Imperative Web Server could allow an unauthenticated attacker with network access to compromise critical data or disrupt services, impacting confidentiality, integrity, and availability. This issue is relevant if Helidon is deployed and accessible via HTTP, as exploitation could lead

CVE advisoryCRITICAL

CVE-2026-73917

Helidon Imperative Web Server Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle's Helidon Imperative Web Server allows unauthenticated attackers with network access to compromise critical data. Successful exploitation could lead to unauthorized creation, deletion, or modification of data, or complete access to all accessible data. This impacts data confidentiality and int

CVE advisoryCRITICAL

CVE-2026-73916

Helidon Imperative Web Server Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Oracle Fusion Middleware's Helidon product, specifically its Imperative Web Server component. This flaw allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to or modify critical data. This could lead to the unauthorized creation, deletion, or alteration

CVE advisoryCRITICAL

CVE-2026-73912

Oracle Helidon Imperative Web Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Helidon's Imperative Web Server component allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. The main concern is confirming relevance and exposure within our

CVE advisoryCRITICAL

CVE-2026-73866

Oracle Helidon Imperative Web Server Data Tampering Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Helidon's Imperative Web Server allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized modification or access of critical data. This issue is categorized as CRITICAL due to its potential impact on data confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-73865

Oracle Helidon Imperative Web Server Data Integrity and Confidentiality Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Helidon's Imperative Web Server, enabling unauthenticated network attackers to access or modify critical data. This could result in unauthorized data changes or complete data access, impacting confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-71167

Helidon Imperative Web Server Remote Data Corruption and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Helidon Imperative Web Server could permit an unauthenticated attacker with network access to compromise critical data, leading to unauthorized modifications or access, and potentially causing partial denial of service.

CVE advisoryCRITICAL

CVE-2026-71166

Oracle Helidon Imperative Web Server Remote Data Manipulation and Denial of Service Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Helidon's Imperative Web Server allows unauthenticated attackers with network access to compromise the product, potentially leading to unauthorized data access, modification, deletion, or partial denial of service. This issue could result in significant data compromise or service disr

CVE advisoryCRITICAL

CVE-2026-71164

Helidon Imperative Web Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle's Helidon Imperative Web Server, allowing unauthenticated network attackers to potentially take over the system. This could impact confidentiality, integrity, and availability. The primary concern is confirming if this technology is exposed in our environment.

CVE advisoryCRITICAL

CVE-2026-71152

Helidon Imperative Web Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Helidon Imperative Web Server component of Oracle Fusion Middleware allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to a complete takeover. This impacts confidentiality, integrity, and availability, necessitating an understandin

CVE advisoryCRITICAL

CVE-2026-71102

Oracle Portable Clusterware Integrity and Availability Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Database Server's Portable Clusterware component allows unauthenticated network attackers to compromise the system via HTTP, potentially leading to unauthorized data modification, deletion, or denial of service. This impacts data integrity and availability, warranting a review of affe

CVE advisoryCRITICAL

CVE-2026-71074

Helidon Imperative Web Server Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability affects the Helidon product, a component of Oracle Fusion Middleware, allowing unauthenticated attackers with network access to potentially take over the system. This could impact confidentiality, integrity, and availability, necessitating a review of network-exposed Helidon instances.

CVE advisoryCRITICAL

CVE-2026-71065

Helidon Imperative Web Server Unauthorized Data Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Oracle's Helidon Imperative Web Server, enabling unauthenticated attackers with network access to potentially compromise critical data and impact other products. This easily exploitable issue could lead to unauthorized access, modification, or deletion of data accessible through Helidon.

CVE advisoryCRITICAL

CVE-2026-71059

Oracle BI Publisher Web Service API Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle BI Publisher's Web Service API could allow a low-privileged attacker with network access to take control of the system, potentially impacting other connected products. This issue, affecting Oracle Analytics, presents a critical risk to reporting and analytics systems.

CVE advisoryCRITICAL

CVE-2026-71040

Oracle Agile PLM Security Vulnerability Allows Unauthenticated Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Agile PLM allows unauthenticated attackers with network access to compromise the system, potentially leading to a complete takeover and significant impacts on confidentiality, integrity, and availability. This issue is reachable via HTTP and requires no prior authentication, making it

CVE advisoryCRITICAL

CVE-2026-71037

Oracle Commerce Guided Search Experience Manager Unauthorized Data Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Commerce Guided Search and Experience Manager allows an unauthenticated attacker to gain unauthorized access to or modify critical data. This issue is reachable externally and requires user interaction, potentially impacting other products. Successful exploitation could lead to unauthorized da

CVE advisoryCRITICAL

CVE-2026-71036

Oracle Commerce Guided Search and Experience Manager Data Tampering Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Commerce Guided Search and Experience Manager to gain unauthorized access to or modify critical data. This could impact e-commerce and content management systems. Confirmation of the affected component's use in the environment is need

CVE advisoryCRITICAL

CVE-2026-71026

Oracle Commerce Guided Search Data Compromise Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search and Experience Manager, allowing unauthenticated attackers with network access to compromise the system. This could lead to unauthorized access, modification, or deletion of critical or all accessible data.

CVE advisoryCRITICAL

CVE-2026-71015

Oracle Commerce Guided Search and Experience Manager Data Tampering Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search/Experience Manager, allowing unauthenticated attackers network access to modify or delete critical data. This could result in unauthorized access to all accessible data. Readers should care because this impacts the confidentiality and integrity of e-comme

CVE advisoryCRITICAL

CVE-2026-71014

Oracle Commerce Guided Search and Experience Manager Data Compromise Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Commerce Guided Search and Experience Manager could permit unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized data modification or access. It is important to confirm if this technology is in use and assess potential exposure to

CVE advisoryCRITICAL

CVE-2026-70998

Oracle Commerce Guided Search and Experience Manager Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Commerce Guided Search and Experience Manager allows unauthenticated network attackers to gain unauthorized access to critical data or modify existing information. This could significantly impact additional products and lead to unauthorized access or modification of accessible data.

CVE advisoryCRITICAL

CVE-2026-70997

Oracle Commerce Experience Manager Network Denial of Service and Data Exposure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Commerce's Experience Manager component, which handles guided search, can be exploited by unauthenticated attackers over a network. This could allow unauthorized access to critical data or cause a complete denial of service by crashing the system. Given this component's common exposure as an i

CVE advisoryCRITICAL

CVE-2026-70995

Oracle Commerce Guided Search / Experience Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search and Experience Manager, allowing unauthenticated attackers with network access to take over the affected components. This issue, impacting the Endeca Application Controller, has a high CVSS score, indicating significant risks to confidentiality, integrity

CVE advisoryCRITICAL

CVE-2026-70994

Oracle Commerce Guided Search Experience Manager Unauthorized Access and Denial of Service Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Guided Search and Experience Manager, allowing unauthenticated attackers with network access to compromise the system. Successful exploitation could result in unauthorized access to critical data or cause a complete denial of service. This issue warrants attention due

CVE advisoryCRITICAL

CVE-2026-70984

Oracle Commerce Content Acquisition System Integrity and Availability Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Commerce's Content Acquisition System allows unauthenticated attackers network access to compromise the system. Successful exploitation can lead to unauthorized modification or deletion of critical data and cause a denial of service.

CVE advisoryCRITICAL

CVE-2026-70981

Oracle Commerce Content Acquisition System Vulnerability Allows Data Tampering and Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Commerce's Content Acquisition System could allow an unauthenticated attacker with network access to modify or delete critical data and cause denial of service. It is uncertain if the affected component is exposed or relevant to your environment.

CVE advisoryCRITICAL

CVE-2026-70980

Oracle Commerce Content Acquisition System Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Oracle Commerce's Content Acquisition System that could allow an unauthenticated attacker to take over Oracle Commerce Guided Search and Experience Manager. While exploitation is difficult, successful attacks may affect other products, potentially leading to significant disruption.

CVE advisoryCRITICAL

CVE-2026-70979

Oracle Commerce Content Acquisition System Data Corruption and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce's Content Acquisition System, allowing unauthenticated attackers with network access to corrupt or delete data, or cause denial of service. This affects Oracle Commerce Guided Search and Experience Manager, potentially impacting the integrity and availability of e-comm

CVE advisoryCRITICAL

CVE-2026-70978

Oracle Commerce Content Acquisition System Vulnerability Allows Data Compromise

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Oracle Commerce's Content Acquisition System that, if exploited by an unauthenticated attacker with network access, could lead to unauthorized access, modification, or deletion of critical data. This issue affects Oracle Commerce Guided Search and Oracle Commerce Experience Manager, potentiall

CVE advisoryCRITICAL

CVE-2026-70976

Oracle Commerce Guided Search Content Acquisition System Integrity and Availability Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Oracle Commerce Guided Search and Experience Manager's Content Acquisition System that an unauthenticated attacker with network access could exploit. This could lead to unauthorized modification or deletion of critical data and cause denial-of-service conditions through system crashes. The iss

CVE advisoryCRITICAL

CVE-2026-70970

Oracle WebCenter Portal Runtime Tools Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal's Runtime Tools component allows unauthenticated network attackers to achieve complete system takeover. This issue impacts confidentiality, integrity, and availability, and should be a concern if Oracle WebCenter Portal is in use.

CVE advisoryCRITICAL

CVE-2026-70958

Oracle Hyperion Infrastructure Technology Installation and Configuration Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Infrastructure Technology's installation and configuration, allowing unauthenticated attackers with network access to potentially take over the system after user interaction. This compromise could extend to other connected products.

CVE advisoryCRITICAL

CVE-2026-70954

Oracle Commerce Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Commerce Platform's Dynamo Application Framework, enabling unauthenticated attackers with network access to achieve complete platform takeover. This impacts confidentiality, integrity, and availability, making it crucial for organizations to assess their exposure and business c

CVE advisoryCRITICAL

CVE-2026-70926

Oracle Workflow Notification Mailer Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Workflow's Notification Mailer component. Unauthenticated attackers with network access via SMTP can exploit this to compromise Oracle Workflow, potentially leading to a complete system takeover with significant impacts on confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-70921

Oracle Hyperion Financial Management Unauthenticated Network Access to Critical Data

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Financial Management could allow unauthenticated attackers with network access to compromise the system, potentially impacting other connected products. Successful exploitation could lead to unauthorized access, modification, or complete compromise of critical financial data.

CVE advisoryCRITICAL

CVE-2026-70920

Oracle Hyperion Financial Management SQL Injection Leading to Full Compromise.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management's security component, allowing a low-privileged attacker with network access to achieve a full system takeover via SQL injection. This could impact connected products and compromise financial data.

CVE advisoryCRITICAL

CVE-2026-70905

Oracle Access Manager SAML Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker with network access via SAML can exploit a vulnerability in Oracle Access Manager's agent infrastructure, potentially leading to a complete system takeover. This critical vulnerability impacts the confidentiality, integrity, and availability of the access management solution.

CVE advisoryCRITICAL

CVE-2026-70884

Oracle Hyperion Data Relationship Management Access and Security Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Data Relationship Management could allow unauthenticated attackers with network access to modify or access critical data. This issue impacts data confidentiality and integrity. The primary concern is confirming if the affected technology is in use.

CVE advisoryCRITICAL

CVE-2026-70883

Oracle Hyperion Data Relationship Management Unauthorized Data Access Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access to potentially modify or delete critical data. This could result in unauthorized access to or complete control over all accessible data within the system. The primary concern is to determine if

CVE advisoryCRITICAL

CVE-2026-70880

Oracle Hyperion Data Relationship Management Access and Security Vulnerability Allows Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Data Relationship Management can be exploited by an unauthenticated attacker with network access, potentially leading to a complete system takeover and impact on other products. This threat is reachable via TCP and poses a significant risk to data and operations.

CVE advisoryCRITICAL

CVE-2026-70876

Oracle Hyperion Data Relationship Management High Privilege Access and Security Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Data Relationship Management allows a high-privilege attacker with network access to compromise the system, potentially impacting other Oracle products. This could result in a complete takeover of the application, affecting its confidentiality, integrity, and availability. Co

CVE advisoryCRITICAL

CVE-2026-70873

Oracle Hyperion Data Relationship Management Access and Security Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Data Relationship Management's access and security components. Unauthenticated attackers with network access can exploit this flaw to gain complete control of the system. This presents a significant risk to data integrity and availability.

CVE advisoryCRITICAL

CVE-2026-70872

Oracle Hyperion Data Relationship Management Access and Security Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Hyperion Data Relationship Management's access and security component. This could lead to unauthorized modification or deletion of critical data, or complete data access, impacting data confidentiality and integrity. Organizations usi

CVE advisoryCRITICAL

CVE-2026-70871

Oracle Hyperion Data Relationship Management Critical Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access to achieve a complete system takeover. This issue impacts the confidentiality, integrity, and availability of the affected product, making it important to confirm if your organization uses this

CVE advisoryCRITICAL

CVE-2026-70862

Oracle Application Testing Suite 13.3.0.1 Data Compromise Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Application Testing Suite that allows unauthenticated attackers with network access to compromise the application. Successful exploitation could lead to unauthorized modification or access to critical data. This issue is relevant due to the potential for significant data integr

CVE advisoryCRITICAL

CVE-2026-70855

Oracle Siebel CRM Self Service Data Tampering and Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Siebel CRM's Siebel Apps - Self Service allows unauthenticated attackers with network access to compromise the system. Successful exploitation, requiring user interaction, can lead to unauthorized modification or deletion of critical data and unauthorized access to all accessible data. This is

CVE advisoryCRITICAL

CVE-2026-70854

Oracle Hyperion Financial Management Security Vulnerability Allows Data Modification and Denial of Service

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Hyperion Financial Management, a financial management product, allows unauthenticated attackers with network access to modify, delete, or create critical data. It can also cause the system to crash, impacting data integrity and availability. The reader should care to confirm if this product is

CVE advisoryCRITICAL

CVE-2026-70846

Oracle Demand Planning Unauthorized Data Access Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Oracle Demand Planning may allow unauthorized access or modification of critical data. This could impact other integrated products, and attackers with network access could exploit it. Confirm relevance and understand exposure to critical data.

CVE advisoryCRITICAL

CVE-2026-70817

Oracle Hyperion Financial Management Security Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers with network access to compromise the system. Successful exploitation could result in a complete takeover, impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-70745

Oracle Hyperion Financial Reporting Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Financial Reporting's server component allows unauthenticated attackers with network access to potentially compromise the system, leading to a complete takeover. This issue poses a high risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-70741

Oracle Hyperion Financial Reporting RMI Authentication Bypass Leading to Data Compromise

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Financial Reporting allows unauthenticated network attackers to compromise the server, potentially leading to unauthorized access, modification, or deletion of critical financial data. This issue warrants attention to determine if the affected product is in use and if it is r

CVE advisoryCRITICAL

CVE-2026-70740

Oracle Hyperion Financial Reporting Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Reporting that allows unauthenticated attackers with network access to potentially take over the system. This could impact the confidentiality, integrity, and availability of financial reporting data. Readers should confirm if Oracle Hyperion Financial Report

CVE advisoryCRITICAL

CVE-2026-70739

Oracle Hyperion Financial Reporting Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Financial Reporting allows unauthenticated network attackers to take over the product. This could result in unauthorized control over financial reporting systems and their data. Attention is warranted given the ease of exploitation and potential for full system compromise.

CVE advisoryCRITICAL

CVE-2026-70730

Oracle Hyperion Profitability and Cost Management Unauthenticated Data Access Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Profitability and Cost Management that allows an unauthenticated attacker with network access to compromise the system. This could lead to unauthorized creation, deletion, modification, or complete access to critical financial data. The reader should care because this

CVE advisoryCRITICAL

CVE-2026-70689

Oracle Essbase Infrastructure Vulnerability Allows Full Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Essbase's Infrastructure component, allowing unauthenticated attackers with network access to compromise the system. Successful exploitation could lead to a complete takeover of Oracle Essbase, impacting data and availability. This is relevant if your organization uses Oracle E

CVE advisoryCRITICAL

CVE-2026-70673

Oracle Reports Developer Security and Authentication Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated attackers with network access to compromise the product, potentially impacting other connected Oracle Fusion Middleware products. Successful exploitation can lead to unauthorized access to critical data or unauthorized modifications of some dat

CVE advisoryCRITICAL

CVE-2026-70669

Oracle Reports Developer Security and Authentication Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer, part of Oracle Fusion Middleware, allows unauthenticated attackers to gain full control of the product via network access. This could impact the availability and integrity of reporting services. Confirm relevance and exposure for this Oracle component.

CVE advisoryCRITICAL

CVE-2026-70668

Oracle Reports Developer Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Reports Developer, part of Oracle Fusion Middleware, allows unauthenticated network attackers to compromise the product. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data. Readers should care because this issue presents a significant risk to da

CVE advisoryCRITICAL

CVE-2026-62988

Froxlor API command exposure allows sensitive data disclosure and account takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Froxlor server administration software has a vulnerability where specific API commands retrieve and return sensitive database fields, including password hashes and two-factor authentication seeds. An authenticated API user with relevant permissions could exploit this to gain unauthorized access to customer and admi

CVE advisoryCRITICAL

CVE-2026-62640

Oracle Reports Developer Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. This could lead to a complete takeover of the product, impacting its confidentiality, integrity, and availability. Uncertainty exists regarding the product's presence and rea

CVE advisoryCRITICAL

CVE-2026-62639

Oracle Reports Developer CORBA Vulnerability Leads to Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Reports Developer could allow unauthenticated attackers with network access to completely compromise the product. This could lead to a takeover of the Oracle Reports Developer environment, impacting confidentiality, integrity, and availability. The potential for such a compromise mean

CVE advisoryCRITICAL

CVE-2026-62638

Oracle Reports Developer Security Authentication Vulnerability Allows Data Tampering and Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated network attacker can compromise Oracle Reports Developer by exploiting a vulnerability in its security and authentication components. This could lead to unauthorized modification or deletion of critical data and cause a denial of service by crashing the product.

CVE advisoryCRITICAL

CVE-2026-62635

Oracle Reports Developer Security and Authentication Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated network attackers to achieve a complete system takeover. This impacts confidentiality, integrity, and availability. The primary concern is determining if this technology is used and accessible within your environment.

CVE advisoryCRITICAL

CVE-2026-62634

Oracle Reports Developer CORBA Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated attacker with network access via CORBA can compromise Oracle Reports Developer, potentially leading to a complete takeover. This vulnerability could impact the confidentiality, integrity, and availability of the Oracle Reports Developer environment. Confirming the use and network exposure of Oracle R

CVE advisoryCRITICAL

CVE-2026-62633

Oracle Reports Developer Security and Authentication Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Reports Developer, allowing unauthenticated network attackers to potentially take over the product. This impacts confidentiality, integrity, and availability. You should care because if this product is used and exposed, attackers could gain control.

CVE advisoryCRITICAL

CVE-2026-62632

Oracle Reports Developer Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker with network access can compromise Oracle Reports Developer, potentially leading to a complete takeover of the product. This vulnerability impacts confidentiality, integrity, and availability, making it crucial to determine if the affected technology is in use and reachable within your envir

CVE advisoryCRITICAL

CVE-2026-62630

Oracle Reports Developer Security and Authentication Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated attackers with network access to compromise the product, potentially leading to a full system takeover and impacting confidentiality, integrity, and availability. Readers should care to confirm if Oracle Reports Developer is in use and accessib

CVE advisoryCRITICAL

CVE-2026-62629

Oracle Reports Developer Security Authentication Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Reports Developer's security and authentication component, potentially leading to unauthorized data access, modification, deletion, or service disruption through denial-of-service attacks.

CVE advisoryCRITICAL

CVE-2026-62626

Oracle Reports Developer Security Authentication Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer, an Oracle Fusion Middleware component, allows unauthenticated network attackers to take over the system via HTTP, potentially impacting confidentiality, integrity, and availability. Confirmation of its use within the environment is essential.

CVE advisoryCRITICAL

CVE-2026-62624

Oracle Reports Developer Takeover via IIOP Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Reports Developer, a component of Oracle Fusion Middleware, allowing unauthenticated network attackers to take over the product. This could impact confidentiality, integrity, and availability. It is important to determine if this product is used and assess its exposure.

CVE advisoryCRITICAL

CVE-2026-62622

Oracle Reports Developer Security and Authentication Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer, part of Oracle Fusion Middleware, allows unauthenticated network attackers to take over the system, impacting confidentiality, integrity, and availability. This poses a significant risk if the component is reachable.

CVE advisoryCRITICAL

CVE-2026-62621

Oracle Reports Developer Security Authentication Vulnerability Leads to Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated network attackers to compromise the product, potentially leading to a full takeover. This impacts the security and authentication components, affecting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-62617

Oracle Reports Developer Security and Authentication Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated network attackers to gain complete control of the component, impacting confidentiality, integrity, and availability. This issue requires confirmation of Oracle Reports Developer's presence and network reachability within the environment.

CVE advisoryCRITICAL

CVE-2026-62614

Oracle Reports Developer Authentication Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated network attackers to take over the system, impacting confidentiality, integrity, and availability. Organizations should confirm if this Oracle Fusion Middleware component is deployed and accessible via HTTP.

CVE advisoryCRITICAL

CVE-2026-62611

Oracle Reports Developer Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated attackers with network access to take over the product, impacting confidentiality, integrity, and availability. The primary concern is determining if this technology is present and accessible within the environment.

CVE advisoryCRITICAL

CVE-2026-62610

Oracle Reports Developer Authentication Bypass Allows Data Corruption and Disclosure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware, allows unauthenticated network attackers to compromise the product. Successful exploitation could lead to unauthorized modification or access to critical data.

CVE advisoryCRITICAL

CVE-2026-62609

Oracle Reports Developer Security and Authentication Vulnerability Allows Takeover

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Reports Developer allows unauthenticated attackers with network access to compromise the product, potentially leading to a complete takeover and impacting data confidentiality, integrity, and availability. It is uncertain if this Oracle component is used within our environment, which

CVE advisoryCRITICAL

CVE-2026-62608

Oracle Reports Developer Security and Authentication Vulnerability Leads to Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Reports Developer allows a low-privileged attacker with network access to take over the product, potentially impacting other connected systems and leading to significant confidentiality, integrity, and availability losses.

CVE advisoryCRITICAL

CVE-2026-62592

Oracle Siebel CRM Open Integration Vulnerability Allows Full Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM's Open Integration component allows an unauthenticated attacker with network access to fully compromise the integration. This could lead to a complete takeover of the system, impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-62588

Oracle Siebel CRM Integration Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Integration could allow a low-privileged attacker with network access to compromise the integration component and potentially other connected products. Successful exploitation could lead to a full takeover of the Siebel CRM Integration, impacting confidentiality, integrity,

CVE advisoryCRITICAL

CVE-2026-62585

Oracle Siebel CRM Administration Data Archival Vulnerability Enables Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Siebel CRM Administration's Data Archival component, allowing unauthenticated network attackers to potentially take over the system. This impacts confidentiality, integrity, and availability, posing a significant risk to business operations.

CVE advisoryCRITICAL

CVE-2026-62582

Oracle Hyperion Calculation Manager Security Vulnerability Enables Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Calculation Manager that could allow a low-privileged attacker with network access to compromise the system. Successful exploitation may result in unauthorized access to, or modification of, critical data within Oracle Hyperion Calculation Manager and potentially impac

CVE advisoryCRITICAL

CVE-2026-62544

Oracle Hyperion Infrastructure Technology Installation and Configuration Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Infrastructure Technology could allow an unauthenticated attacker with network access to completely take over the affected system. This could impact the confidentiality, integrity, and availability of the technology.

CVE advisoryCRITICAL

CVE-2026-62543

Oracle Hyperion Infrastructure Technology Installation and Configuration Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Infrastructure Technology's installation and configuration component allows unauthenticated network attackers to take over the system. This issue, accessible via HTTP, poses a significant risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-62541

Oracle Hyperion Infrastructure Technology Installation and Configuration Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Infrastructure Technology's installation and configuration components. Unauthenticated attackers with network access can exploit this to take over the system, impacting confidentiality, integrity, and availability. The potential for widespread compromise necessitates u

CVE advisoryCRITICAL

CVE-2026-62539

Oracle Hyperion Installation and Configuration Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Infrastructure Technology's installation and configuration components allows an unauthenticated attacker with network access to potentially take over the system. This could impact confidentiality, integrity, and availability. You should care because financial planning and rep

CVE advisoryCRITICAL

CVE-2026-62512

Oracle Siebel CRM Cloud Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component could allow a low-privileged attacker with network access to take over the application. Successful exploitation, reachable via HTTP, may also impact other connected products, leading to significant data compromise and a ful

CVE advisoryCRITICAL

CVE-2026-62463

Oracle Hyperion Lifecycle Management Unauthorized Data Access Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Infrastructure Technology allows a low-privileged attacker with network access to compromise the system, leading to unauthorized modification or deletion of critical data. Attacks could also significantly impact additional Oracle Hyperion products. Successful exploitation cou

CVE advisoryCRITICAL

CVE-2026-62457

Oracle Hyperion Infrastructure Technology Common Events Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Infrastructure Technology's Common Events component, allowing unauthenticated network attackers to achieve a complete system takeover. This could impact confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-62452

Oracle Siebel CRM Cloud Manager Unauthenticated Network Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Cloud Applications allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized access to critical data, modification of data, or partial denial of service. The impact may extend to additional products connected to Siebe

CVE advisoryCRITICAL

CVE-2026-61318

Oracle Siebel CRM Cloud Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Siebel CRM Cloud Applications, affecting the Siebel Cloud Manager component. An unauthenticated attacker with network access could exploit this to achieve a full takeover of the application, impacting confidentiality, integrity, and availability. It is important to determine if

CVE advisoryCRITICAL

CVE-2026-61317

Oracle Siebel CRM Cloud Manager Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component allows low-privileged attackers with network access to potentially take over the application and impact other products. The issue, which is easily exploitable via HTTP, poses a high risk to confidentiality, integrity, and a

CVE advisoryCRITICAL

CVE-2026-61272

Oracle JD Edwards Web Runtime SEC Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools' Web Runtime component. Unauthenticated attackers with network access can exploit this to take over the system, impacting confidentiality, integrity, and availability. This issue requires attention due to its potential to disrupt business operatio

CVE advisoryCRITICAL

CVE-2026-61258

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Internet Directory's LDAP server could allow an unauthenticated attacker with network access to compromise the system, potentially leading to a complete takeover. This issue affects widely used versions and poses a significant risk to directory services.

CVE advisoryCRITICAL

CVE-2026-61248

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Internet Directory's LDAP Server component allows a low-privileged attacker with network access to achieve a full takeover of the directory service. This compromise could significantly impact other products that rely on Oracle Internet Directory for authentication and authorization.

CVE advisoryCRITICAL

CVE-2026-61206

Oracle Hyperion Calculation Manager Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Calculation Manager's security component, allowing a low-privileged attacker with network access to compromise the system. Successful exploitation could lead to a complete takeover of Calculation Manager, potentially impacting other related products.

CVE advisoryCRITICAL

CVE-2026-61066

Oracle Identity Manager Legacy UI RMI Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Identity Manager's legacy UI, allowing a low-privileged attacker with network access via RMI to compromise the system. This could lead to a takeover of Oracle Identity Manager and potentially impact other products, affecting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-61021

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows a low-privileged attacker with network access to compromise the system, potentially impacting other products. Successful exploitation could lead to a complete takeover of Oracle WebCenter Sites, affecting its confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-61018

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover. The issue is easily exploitable via HTTP and impacts confidentiality, integrity, and availability. Readers should confirm if Oracle WebCenter Sites is

CVE advisoryCRITICAL

CVE-2026-61008

Oracle WebCenter Sites Unauthorized Data Access and Modification Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites could allow unauthenticated attackers to gain unauthorized access to or modify critical data. This issue is reachable via network access and poses a risk of data compromise. The primary concern is to determine if this technology is in use and assess the potential expos

CVE advisoryCRITICAL

CVE-2026-61003

Oracle Managed File Transfer MFT Runtime Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Managed File Transfer's MFT Runtime Server component. A low-privileged attacker with network access could exploit this to take over the system, potentially impacting other products and leading to significant confidentiality, integrity, and availability issues.

CVE advisoryCRITICAL

CVE-2026-61001

Oracle Web Services Manager Improper Access Control Leading to Data Compromise

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Web Services Manager, an Oracle Fusion Middleware component, could allow a low-privileged attacker with network access to modify or access sensitive data. This could potentially impact other connected products, raising concerns about data integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-60995

Oracle Identity Manager Connector Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Identity Manager Connector could allow a low-privileged attacker with network access to take over the product, potentially impacting other connected systems. This could result in significant risks to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60990

Oracle Identity Manager Connector Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. This issue allows a low-privileged attacker with network access to potentially take over the connector, impacting its confidentiality, integrity, and availability. The compromise could also significantly affec

CVE advisoryCRITICAL

CVE-2026-60977

Oracle WebLogic Server RMI Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebLogic Server, a core component of Oracle Fusion Middleware. Unauthenticated attackers with network access can exploit this issue via RMI to achieve complete takeover of the affected server, impacting confidentiality, integrity, and availability. This risk warrants attention

CVE advisoryCRITICAL

CVE-2026-60971

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, could allow an unauthenticated attacker with network access to take over the system. This could impact confidentiality, integrity, and availability. Further details on specific versions and exploitability are not provided

CVE advisoryCRITICAL

CVE-2026-60970

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture allows unauthenticated attackers with network access to potentially take over the system. This could impact confidentiality, integrity, and availability. Its relevance depends on whether this Oracle product is deployed and reachable in your environment.

CVE advisoryCRITICAL

CVE-2026-60958

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, allowing unauthenticated network attackers to potentially take over the system. This could impact data confidentiality, integrity, and availability. The primary concern is determining if this technology is in use and assessing its exposure.

CVE advisoryCRITICAL

CVE-2026-60947

Oracle WebCenter Enterprise Capture RMI Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture allows unauthenticated attackers network access to take over the system, impacting confidentiality, integrity, and availability. It's important to verify if this technology is used and assess its exposure to confirm relevance.

CVE advisoryCRITICAL

CVE-2026-60921

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, allowing unauthenticated network attackers to take over the system. This could impact confidentiality, integrity, and availability, warranting a review of its relevance and exposure within your infrastructur

CVE advisoryCRITICAL

CVE-2026-60916

Oracle WebCenter Enterprise Capture HTTP Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture allows unauthenticated network attackers to access, modify, or delete critical data, and potentially cause a partial denial of service. The exploit may impact additional products beyond Oracle WebCenter Enterprise Capture itself.

CVE advisoryCRITICAL

CVE-2026-60905

Oracle WebCenter Content Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle WebCenter Content allows unauthenticated attackers with network access to compromise the system if a user interacts with malicious content. This could lead to unauthorized modification or access to critical data and a partial denial of service, potentially impacting other connected products.

CVE advisoryCRITICAL

CVE-2026-60861

Oracle Fusion Middleware Service Delivery Platform Messaging Enabler Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows a low-privileged attacker with network access to compromise the system. This could lead to unauthorized access, modification, or deletion of critical data and may impact other connected products.

CVE advisoryCRITICAL

CVE-2026-60858

Oracle Hyperion Calculation Manager Security Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Calculation Manager allows unauthenticated network attackers to gain complete control of the system. This easily exploitable flaw, reachable via HTTP, could lead to a full system takeover, impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60821

Oracle PeopleSoft Business Interlink Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle PeopleSoft's Business Interlink component allows unauthenticated attackers with network access to potentially take over the entire system. This could impact confidentiality, integrity, and availability. Security-aware leaders should confirm if their PeopleSoft systems are exposed and

CVE advisoryCRITICAL

CVE-2026-60782

Oracle E-Business Suite Payments File Transmission Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Payments, part of Oracle E-Business Suite, allowing unauthenticated attackers with network access to take over the system. This easily exploitable issue impacts confidentiality, integrity, and availability, posing a significant risk to the affected application.

CVE advisoryCRITICAL

CVE-2026-60754

Oracle Siebel CRM Marketing Vulnerability Allows Unauthorized Access and Denial of Service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Siebel CRM's Marketing component allows unauthenticated attackers with network access to gain unauthorized access to critical data or cause denial-of-service conditions. This issue is easily exploitable and requires immediate attention due to potential impacts on data confidentiality

CVE advisoryCRITICAL

CVE-2026-60737

Oracle Web Services Manager Unauthorized Data Access Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Web Services Manager could allow an unauthenticated attacker with network access to gain unauthorized access to or modify critical data. This issue impacts Oracle Fusion Middleware and is relevant for technical readers and security-aware leaders to understand potential data compromise

CVE advisoryCRITICAL

CVE-2026-60730

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal allows a low-privileged attacker with network access to potentially take over the affected system, impacting confidentiality, integrity, and availability. The scope of this issue may extend beyond the immediate product, leading to a full takeover of Oracle WebCenter P

CVE advisoryCRITICAL

CVE-2026-60728

Oracle WebCenter Portal Portlet Services Vulnerability Allows Data Access and Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle WebCenter Portal's Portlet Services allows unauthenticated network attackers to access critical data or cause denial of service. This issue is reachable via HTTP and could lead to data exposure or service unavailability.

CVE advisoryCRITICAL

CVE-2026-60727

Oracle Identity Manager Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Identity Manager allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover. This could impact the confidentiality, integrity, and availability of identity management functions.

CVE advisoryCRITICAL

CVE-2026-60721

Oracle Identity Manager OIM Legacy UI Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Identity Manager, an Oracle Fusion Middleware component. This issue enables unauthenticated attackers with network access via HTTP to compromise the entire system, potentially leading to a full takeover. The vulnerability impacts confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60720

Oracle Identity Manager OIM Legacy UI Vulnerability Allows Full Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Identity Manager allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to a full takeover and impacting other connected products. This issue poses significant risks to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-60698

Oracle WebLogic Server IIOP Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access to take over the server, impacting confidentiality, integrity, and availability. Oracle Fusion Middleware's Core component is affected, and successful exploitation could lead to a complete server compromise. Confirma

CVE advisoryCRITICAL

CVE-2026-60672

Oracle WebLogic Server Core Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access to compromise the server, potentially leading to a complete takeover. This easily exploitable flaw impacts confidentiality, integrity, and availability, and is reachable via T3 and IIOP protocols.

CVE advisoryCRITICAL

CVE-2026-60591

Oracle Hospitality Simphony Network Vulnerability Allows Critical Data Tampering and Denial of Service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hospitality Simphony, a point-of-sale system component, allowing unauthenticated attackers with network access to modify or delete critical data and cause denial of service. The issue is reachable via HTTP, posing a risk to data integrity and system availability.

CVE advisoryCRITICAL

CVE-2026-67443

FUXA Authorization Bypass Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in FUXA, a web-based SCADA/HMI/Dashboard software, allows unauthenticated remote attackers to bypass authorization controls. This could enable them to access sensitive system functions, deploy malicious scripts, and potentially execute operating system commands, compromising project data and sy

CVE advisoryCRITICAL

CVE-2026-57826

openHiTLS Certificate Verification Flaw Allows Spoofing

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The openHiTLS library has a vulnerability in its X.509 certificate chain verification process that fails to properly validate older certificate formats, potentially allowing untrusted certificates to be accepted and undermining secure communication channels.

CVE advisoryCRITICAL

CVE-2026-52735

Zebra Node Consensus Split Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in the ZEBRA Zcash node implementation where it may incorrectly count signature operations in specific transaction types. This could allow an attacker to broadcast transactions that an affected ZEBRA node accepts, while the reference implementation rejects them, potentially causing a consensus ch

CVE advisoryCRITICAL

CVE-2026-55166

Lemur SSRF and Authorization Weakness Exposes Cloud Credentials and Private Keys.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Lemur, a TLS certificate management tool, has a vulnerability allowing authenticated users to make backend requests to internal services. This could expose cloud credentials and private keys due to server-side request forgery and authorization weaknesses. The issue is fixed in version 1.9.2.

CVE advisoryCRITICAL

CVE-2026-75625

Kraken Agents Cache Poisoning Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Kraken agents may be vulnerable to cache poisoning due to improper verification of downloaded content, potentially allowing malicious container images to be distributed and executed internally. This occurs when attackers supply substituted content that bypasses integrity checks, leading to poisoned caches that can re-s

CVE advisoryCRITICAL

CVE-2026-71879

GBIF Integrated Publishing Toolkit Authentication Bypass Allows Administrative Control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the GBIF Integrated Publishing Toolkit allows remote attackers to bypass authentication during initial setup, potentially leading to administrative control. This issue is present before the first reboot and is a concern if the setup functionality is exposed. Confirmation of relevance and exp

CVE advisoryCRITICAL

CVE-2026-71878

Missing Authentication in GBIF IPT Allows Administrative Control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the GBIF Integrated Publishing Toolkit where missing authentication in its initial setup functionality can be exploited to gain administrative control. This issue allows remote attackers to bypass authentication and potentially control the system if the setup remains accessible after initial c

CVE advisoryCRITICAL

CVE-2026-66780

Submariner-Operator Excessive Permissions Enable Man-in-the-Middle Attacks

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in the submariner-operator component grants excessive permissions, potentially allowing a compromised cluster to redirect inter-cluster traffic and enable Man-in-the-Middle attacks. This vulnerability affects network configurations and endpoint information within a cluster mesh.

CVE advisoryCRITICAL

CVE-2026-52610

Reportico Arbitrary File Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file write vulnerability in reportico-web allows remote attackers to create or overwrite files on the server. This could compromise system integrity and data security. It is important to determine if this software is used within the organization to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-52608

Reportico Remote Code Execution via Access Control Flaw.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in reportico-web allows unauthenticated attackers to inject arbitrary PHP code into report attributes, potentially leading to remote code execution. This could affect service behavior and sensitive information if the vulnerability is present and reachable. Confirmation of the t

CVE advisoryCRITICAL

CVE-2026-50161

Libre WebSocket Integer Overflow Leads to Heap Corruption.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical integer overflow vulnerability in a real-time communications library can allow network-accessible attackers to corrupt heap memory or cause denial of service in WebSocket servers. This could impact the integrity and availability of services that rely on these communications.

CVE advisoryCRITICAL

CVE-2026-67271

Dell PowerStore Out-of-bounds Write Vulnerability in SMB/CIFS

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Dell PowerStore storage systems have a critical vulnerability in their network file sharing component that could allow an unauthenticated attacker to cause a denial of service or potentially execute remote code. This issue could lead to system crashes, persistent outages if automatic restarts are enabled, and a more so

CVE advisoryCRITICAL

CVE-2026-57580

Authentik SAML Source Account Takeover via XML Comment Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentik identity provider vulnerability allows an attacker with an account on a source identity provider to hijack existing user accounts by injecting an XML comment into the NameID. This grants full takeover without requiring credentials or private keys. The issue is mitigated by ensuring the SAML Source is not c

CVE advisoryCRITICAL

CVE-2026-52723

ePA 3.x Integration Improper Certificate Validation Allows VAU Server Impersonation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The ePA 3.x Integration component, responsible for managing medical information for Germany's electronic patient records, has a vulnerability where it improperly validates server certificates. A network attacker could intercept VAU handshake communications, impersonate the VAU server, and read or modify encrypted traff

CVE advisoryCRITICAL

CVE-2026-18963

Keycloak Keycloak-Services Password Reset Flaw Allows Account Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A flaw in the password reset process of the keycloak-services component allows an unauthenticated attacker to bypass email verification and directly set new credentials for any user account, potentially leading to full account takeover.

CVE advisoryCRITICAL

CVE-2026-45118

MyBB Contact Module Open Redirect and JavaScript Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MyBB forum software contains a vulnerability in its Contact module that allows for open redirects and reflected JavaScript code injection. An attacker could exploit this by tricking a user into clicking a crafted link, potentially leading to script execution in the user's browser. This could result in a compromised use

CVE advisoryCRITICAL

CVE-2026-45117

MyBB Installer PHP Code Injection Leading to Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the installer for MyBB forum software could allow attackers to inject PHP code and execute it remotely on affected servers. This occurs when specially crafted database configuration values are provided during the installation process, and the installer does not properly escape these inputs. The prima

CVE advisoryCRITICAL

CVE-2026-75784

TRENDnet TEW-WLC100 HTTP Header Handler Stack Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow vulnerability exists in a TRENDnet wireless controller's HTTP header handler. Attackers can exploit this remotely by manipulating an argument in specially crafted HTTP requests. This could potentially impact the device's services, and public exploit code increases the risk.

CVE advisoryCRITICAL

CVE-2026-74015

Readabler Plugin SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Readabler, potentially allowing attackers to access or manipulate database information. The reachability of this flaw is likely external, making it a concern for internet-facing web applications utilizing the affected software.

CVE advisoryCRITICAL

CVE-2026-73996

Masteriyo LMS Unauthenticated Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated arbitrary file upload vulnerability exists in a WordPress Learning Management System plugin. This flaw could allow an attacker to upload malicious files, potentially leading to system compromise. This is relevant for organizations using this plugin, as it impacts the security of their educational pla

CVE advisoryCRITICAL

CVE-2026-73392

Super Store Finder SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Super Store Finder plugin, potentially allowing attackers to access or manipulate plugin data without authentication. Given the plugin's function, it is likely exposed externally, posing a risk of data compromise and operational disruption. Confirming its pre

CVE advisoryCRITICAL

CVE-2026-73381

Popup by Supsystic Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated broken authentication vulnerability exists in the Popup by Supsystic WordPress plugin. Reachable via the network, this flaw could allow unauthorized access and system modifications without requiring user credentials. This issue is relevant to website owners and administrators, potentially imp

CVE advisoryCRITICAL

CVE-2026-73380

Popup by Supsystic PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Popup by Supsystic WordPress plugin that allows unauthenticated PHP object injection. This could lead to arbitrary code execution on the server if reachable, potentially allowing unauthorized access and data manipulation. Confirmation of the plugin's use within the environment and

CVE advisoryCRITICAL

CVE-2026-73376

Ultimate Maps by Supsystic Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in Ultimate Maps by Supsystic. Reachable instances could allow attackers to execute arbitrary code, potentially compromising the web application and its data. Identifying and assessing the risk of any deployed instances is advised.

CVE advisoryCRITICAL

CVE-2026-73366

Easy Google Maps Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Easy Google Maps plugin. If reachable, an attacker could inject malicious code, potentially leading to unauthorized code execution or data compromise. This affects public-facing websites utilizing the plugin for mapping features.

CVE advisoryCRITICAL

CVE-2026-73365

JetAppointment Unauthenticated SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the JetAppointment plugin, potentially allowing attackers to access or modify sensitive data without credentials. This issue could impact data integrity and service availability if the plugin is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-73355

SQL Injection in Affiliates Manager Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in the Affiliates Manager technology allows attackers to inject commands into the database. This could lead to unauthorized access to sensitive data. The primary concern is to identify if this technology is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-73343

WP Compress Unauthenticated Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the WP Compress WordPress plugin allows unauthenticated attackers to execute arbitrary code remotely. This could lead to a complete compromise of affected systems. It is important to determine if this plugin is in use and reachable within your environment.

CVE advisoryCRITICAL

CVE-2026-73341

RegistrationMagic PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in a registration plugin, potentially allowing attackers to execute arbitrary code and compromise systems. This could impact website integrity and data, making it crucial to identify its presence and assess exposure.

CVE advisoryCRITICAL

CVE-2026-73339

Modern Events Calendar Unauthenticated SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Modern Events Calendar plugin, potentially allowing attackers to access or alter database information. This issue is relevant for internet-facing websites displaying event details and could impact data integrity and service availability. Confirming its use an

CVE advisoryCRITICAL

CVE-2026-73187

Sticky Chat Widget Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Sticky Chat Widget, allowing attackers to execute arbitrary SQL commands. This could lead to unauthorized access to or modification of sensitive data, impacting web applications with public-facing components. Determining the relevance and exposure of this wid

CVE advisoryCRITICAL

CVE-2026-66627

GP Premium Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in GP Premium, a WordPress plugin, that allows unauthorized file uploads. This could enable attackers to execute arbitrary code on the server, potentially compromising website integrity and data. The main concern is determining if this plugin is in use and assessing the associated risk.

CVE advisoryCRITICAL

CVE-2026-59940

Seroval Deserialization Vulnerability Allows Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the Seroval JavaScript utility library, allowing for remote code execution. Attackers can exploit this by sending specially crafted JSON data, which, when deserialized with enabled plugins, can lead to unintended server-side actions or code execution.

CVE advisoryCRITICAL

CVE-2026-32474

Templatiq Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in a Templatiq plugin, potentially allowing attackers to upload malicious files and execute code. This could impact web application integrity and availability. Identifying affected instances is crucial for risk assessment and remediation.

CVE advisoryCRITICAL

CVE-2026-32470

FundEngine Unauthenticated PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in FundEngine, potentially allowing remote code execution or system compromise without authentication. This issue is relevant to organizations using this technology and necessitates confirming its presence and exposure.

CVE advisoryCRITICAL

CVE-2026-32463

Sync Post With Other Site Plugin Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in the Sync Post With Other Site WordPress plugin, potentially allowing an authenticated user to upload malicious files and compromise the affected system. The vulnerability is reachable via network access.

CVE advisoryCRITICAL

CVE-2026-32444

Cwicly Plugin Contributor Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Cwicly website development tool that allows for remote code execution. If reachable, an attacker could exploit this flaw to run arbitrary code on affected systems, potentially compromising the website and its data. It is important to determine if Cwicly is in use within your envir

CVE advisoryCRITICAL

CVE-2026-28192

Piotnet Addons For Elementor Pro Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Piotnet Addons For Elementor Pro allows unauthenticated arbitrary file uploads, potentially leading to unauthorized code execution and compromise of website integrity. This could impact website content and data if the plugin is reachable.

CVE advisoryCRITICAL

CVE-2026-75874

Firefox and Thunderbird Remote Settings Client Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical sandbox escape vulnerability exists in the Remote Settings Client component of user-facing applications. If reachable, this could allow an attacker to break out of a restricted environment, potentially impacting system and user data. Further analysis is needed to determine the exact exploitability and busine

CVE advisoryCRITICAL

CVE-2026-74990

Thunderbird Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Certain versions of Mozilla Thunderbird contain critical memory corruption vulnerabilities due to internal bugs. If reachable, these could potentially lead to application instability or compromise. Confirming the presence of affected software and assessing potential exposure is advised.

CVE advisoryCRITICAL

CVE-2026-74988

Thunderbird Memory Corruption Vulnerabilities Addressed

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory corruption vulnerabilities were found in Thunderbird, potentially allowing exploitation with sufficient effort. These issues have been fixed in newer versions. While the attack vector is network-based, the context suggests limited direct business impact for this desktop application.

CVE advisoryCRITICAL

CVE-2026-74987

Thunderbird Memory Corruption Vulnerabilities Addressed

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Memory corruption vulnerabilities were found in certain Thunderbird versions. If reachable, these flaws could potentially be exploited, though the specific impact is uncertain. The primary concern is to identify if these versions are in use within the organization.Memory corruption vulnerabilities have been identified

CVE advisoryCRITICAL

CVE-2026-74985

Enterprise Policies Privilege Escalation in Mozilla Firefox and Thunderbird

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A privilege escalation vulnerability in the Enterprise Policies component could allow an attacker to gain higher access levels. The reachability and relevance of this vulnerability to the environment require further assessment to understand potential impacts on system configurations and control.A privilege escalation v

CVE advisoryCRITICAL

CVE-2026-74979

Firefox and Thunderbird Add-ons Manager Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A mitigation bypass in the Add-ons Manager component allows bypassing security controls, potentially impacting application integrity and data. This vulnerability is reachable via the network and could lead to high impact, although its relevance to specific deployed software requires confirmation.

CVE advisoryCRITICAL

CVE-2026-74964

Integer Overflow in Firefox and Thunderbird Graphics Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability exists in the Graphics component of widely used browsers and email clients. If reachable, this flaw could allow an attacker to compromise system confidentiality, integrity, and availability. Organizations should confirm if they use the affected software to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-74961

Web Audio Side-Channel Vulnerability in Firefox and Thunderbird

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A side-channel vulnerability exists in the Web Audio component of affected applications. This could potentially allow for sensitive information to be inferred if a user encounters malicious content, though its direct reachability and business impact are still under analysis. Understanding the relevance to your environm

CVE advisoryCRITICAL

CVE-2026-74943

Use-after-free Vulnerability in Mozilla Graphics ImageLib Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird. This issue could allow an attacker to execute arbitrary code if a user processes a specially crafted image file. This impacts the integrity, availability, and potentially confidentiality of affected systems.

CVE advisoryCRITICAL

CVE-2026-74940

Firefox and Thunderbird Use-After-Free Vulnerability in Graphics Text Component.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the Graphics: Text component of Firefox and Thunderbird. If reachable, this could allow for arbitrary code execution, potentially impacting confidentiality, integrity, and availability. This issue affects common user applications and requires assessment for relevance to your dep

CVE advisoryCRITICAL

CVE-2026-74938

Firefox and Thunderbird Mitigation Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical mitigation bypass vulnerability exists in the JavaScript garbage collection component of affected browsers and email clients. This could allow an attacker to bypass security measures and potentially lead to unauthorized disclosure and modification of sensitive information, although direct exploitation is con

CVE advisoryCRITICAL

CVE-2026-74936

Use-after-free Vulnerability in Mozilla Firefox and Thunderbird JavaScript Component

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in the WebAssembly component of Firefox and Thunderbird could allow an attacker to execute arbitrary code. This impacts the integrity and availability of affected applications. The vulnerability is reachable if a user encounters specially crafted content.

CVE advisoryCRITICAL

CVE-2026-75852

ArcadeDB MongoDB Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ArcadeDB's MongoDB wire-protocol plugin allows unauthenticated attackers to bypass SASL authentication on data commands. Attackers can connect to port 27017 without credentials to insert, find, update, delete, or create data in any database. This could lead to unauthorized data access and mo

CVE advisoryCRITICAL

CVE-2026-75851

ArcadeDB Server Authentication Bypass via Asynchronous Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in ArcadeDB server allows an authenticated user with read-only access to escalate privileges to full administrative control. This occurs when asynchronous commands fail to propagate the authenticated principal, causing authorization checks to be bypassed. Exploitation could lead t

CVE advisoryCRITICAL

CVE-2026-75843

ArcadeDB gRPC Transaction Vulnerability Allows Unrestricted JavaScript Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

ArcadeDB has a critical vulnerability in its gRPC transaction executor that allows authenticated readers to run unauthorized JavaScript, potentially creating administrator accounts. Confirmation is needed to determine if this technology is used and reachable within the environment.

CVE advisoryCRITICAL

CVE-2026-75837

Grav Group Access Field Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Grav allows a delegated administrator to escalate to super-admin privileges by manipulating group access settings. This escalation enables unauthorized control, including scheduler and Twig evaluation capabilities, potentially leading to full system compromise. Readers should care because this could

CVE advisoryCRITICAL

CVE-2026-75828

Grav Stored Cross-Site Scripting via Unquoted Attribute Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in Grav, allowing authenticated editors to inject malicious code that executes in visitor browsers when content is rendered. This could impact user trust and data integrity. Confirm relevance and exposure for Grav installations.

CVE advisoryCRITICAL

CVE-2026-75827

Grav Arbitrary File Write Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Grav allows attackers with page-edit or blueprint-config access to achieve remote code execution by writing arbitrary PHP code to web-accessible files via a data directive. This matters for public-facing sites and could lead to server compromise.

CVE advisoryCRITICAL

CVE-2026-75627

Bastillion Authentication Bypass via Path Prefix Routing Mismatch

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Bastillion's controller dispatcher has a vulnerability allowing unauthenticated users to bypass authentication by prefixing request URIs. This could grant attackers access to administrative functions, enabling them to read user listings, create manager accounts, and register managed systems, thus controlling SSH access

CVE advisoryCRITICAL

CVE-2026-34884

Apache SkyWalking MCP SSRF and GraphQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Apache SkyWalking MCP, impacting its ability to securely manage observability data. This issue, involving server-side request forgery and GraphQL expression injection, could allow an attacker to redirect network requests and potentially execute arbitrary code. Organizations should ass

CVE advisoryCRITICAL

CVE-2026-15748

Forminator Forms Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Forminator Forms WordPress plugin has a critical vulnerability that allows unauthenticated attackers to upload and execute arbitrary files by exploiting insufficient file type validation. This could enable remote code execution on affected systems, posing a significant security risk.