NVD disclosure day

Published threat advisories for August 19, 2026

CVE advisoryCRITICAL

CVE-2026-76850

LMDeploy Remote Code Execution via Unsafe Pickle Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

LMDeploy's disaggregated serving feature is vulnerable to arbitrary code execution due to unsafe deserialization of messages. An unauthenticated remote attacker can exploit this by controlling a peer to send malicious data, leading to code execution in the engine process if disaggregated serving is enabled and exposed.

CVE advisoryCRITICAL

CVE-2026-76404

Splunk MCP Server Command Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the Splunk MCP Server app allows an authenticated administrator to execute arbitrary commands on the operating system. This occurs due to missing input validation in the credential management component, which deserializes stored data without proper checks. This could impact system data and s

CVE advisoryCRITICAL

CVE-2026-76312

Splunk Enterprise Embedded Report Session Material Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Splunk Enterprise allows an unauthenticated user to access sensitive data and affect system integrity by exploiting how embedded reports handle session material in archived search jobs. This occurs due to improper authorization enforcement on dispatch archive downloads, potentially exposing session d

CVE advisoryCRITICAL

CVE-2026-76311

Splunk Enterprise Dispatch Archive Download Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Splunk Enterprise allows unauthenticated users with embedded report tokens to download dispatch archives, potentially exposing sensitive data and affecting system integrity because authorization checks may not block download requests early enough.

CVE advisoryCRITICAL

CVE-2026-76310

Splunk Enterprise Embedded Report Token Allows Data Access and System Integrity Impact

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Splunk Enterprise allows unauthenticated users with an embedded report token to download sensitive data and potentially impact system integrity. This occurs because the REST API does not block dispatch archive download requests for embedded reports. If the report owner has administrative privileges,

CVE advisoryCRITICAL

CVE-2026-75595

Netty SNI TLS Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Netty framework allows unauthenticated attackers to bypass mutual TLS authentication if specific per-SNI configurations are used. This bypass can occur due to an incorrect offset check during the TLS handshake, leading to the use of a default rather than a SNI-specific security context.

CVE advisoryCRITICAL

CVE-2026-53548

Termix Host Credential Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Termix server management platform allows authenticated users to obtain SSH or sudo passwords for other users by exploiting an oversight in host ownership verification. This could enable unauthorized access to managed systems outside the Termix instance.

CVE advisoryCRITICAL

CVE-2026-53546

Termix Improper Access Control Vulnerability Discloses SSH Credentials

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Termix server management platform allows authenticated low-privileged users to disclose stored SSH credentials by tricking the system into connecting to an attacker-controlled server. This could expose sensitive user password or private key material. Confirmation of Termix usage and its external

CVE advisoryCRITICAL

CVE-2026-53545

Termix Command Injection Vulnerability in Tunnel Disconnect

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Termix, a web-based server management platform, has a vulnerability where an authenticated user could inject commands by editing a tunnel host field. When a tunnel disconnects, these injected commands may execute on the source SSH host with the privileges of the SSH account. This issue impacts the platform's ability to

CVE advisoryCRITICAL

CVE-2026-55085

Etherpad Stored Cross-Site Scripting via Unsanitized Numbered List Start Attribute.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Etherpad, a real-time collaborative editor, has a vulnerability where malicious markup can be stored in a pad. When another user opens the pad or accesses the timeslider, this markup can execute as cross-site scripting. This could potentially lead to unauthorized actions or data compromise.

CVE advisoryCRITICAL

CVE-2026-22306

Ozols SQL Client Update Domain Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Ozols Grupa OZOLS on Windows due to an abandoned auto-update domain, potentially allowing unauthorized code downloads, untrusted functionality inclusion, and cleartext transmission of sensitive information. This impacts the automatic update channel, affecting system integrity and potentially l

CVE advisoryCRITICAL

CVE-2026-16919

IBM AIX and PowerVM VIOS Improper Pointer Validation Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM AIX and PowerVM VIOS have a vulnerability allowing remote code execution due to improper validation of network-supplied pointers. If reachable, this could permit an attacker to execute arbitrary code, potentially compromising systems. This issue warrants attention to confirm if affected IBM systems are in use and e

CVE advisoryCRITICAL

CVE-2026-16913

IBM AIX and PowerVM VIOS Stack Buffer Overflow Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack buffer overflow vulnerability in IBM AIX and IBM PowerVM VIOS could allow a remote attacker to execute arbitrary code. This could potentially impact the confidentiality, integrity, and availability of affected systems if they are reachable over a network.

CVE advisoryCRITICAL

CVE-2026-16894

IBM AIX and PowerVM VIOS Stack Buffer Overflow leads to Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack buffer overflow vulnerability affects IBM AIX and IBM PowerVM VIOS, potentially allowing remote attackers to execute arbitrary code. This could impact system integrity and availability if the vulnerable systems are reachable. Confirming the presence of these IBM products in your environment is crucial for under

CVE advisoryCRITICAL

CVE-2026-16882

IBM AIX and PowerVM VIOS OS Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in IBM AIX and IBM PowerVM VIOS could allow attackers to run commands remotely. This could impact system confidentiality, integrity, and availability if these products are in use and accessible over the network. Organizations should verify if affected systems are deployed and assess potential e

CVE advisoryCRITICAL

CVE-2026-16872

IBM AIX and PowerVM VIOS Stack Buffer Overflow Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in IBM AIX and IBM PowerVM VIOS that could permit remote attackers to execute arbitrary code. This stack-based buffer overflow requires no authentication or user interaction to exploit, potentially affecting system integrity and confidentiality. Organizations should assess the relevance

CVE advisoryCRITICAL

CVE-2026-16864

IBM AIX and PowerVM VIOS Stack Buffer Overflow Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack buffer overflow in IBM AIX and IBM PowerVM VIOS may allow a remote attacker to execute arbitrary code. This vulnerability impacts critical IBM server and virtualization components. Understanding its relevance is important due to the potential for code execution if reachable.

CVE advisoryCRITICAL

CVE-2026-16862

IBM AIX and PowerVM Stack Buffer Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical stack buffer overflow vulnerability exists in IBM AIX and IBM PowerVM VIOS, allowing remote attackers to execute arbitrary code. This could compromise system integrity and availability if the affected systems are reachable over a network. It is important to determine if these IBM products are deployed in you

CVE advisoryCRITICAL

CVE-2026-16845

IBM AIX and PowerVM VIOS Heap Buffer Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM AIX and PowerVM VIOS have a heap buffer overflow vulnerability that could allow remote attackers to execute arbitrary code. This could lead to a system compromise if the affected technology is reachable via a network. It is important to verify if these systems are in use and exposed to potential risks.

CVE advisoryCRITICAL

CVE-2026-16840

IBM AIX and PowerVM VIOS Out-of-Bounds Write Leads to Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM AIX and PowerVM VIOS have a critical vulnerability allowing remote attackers to execute arbitrary code due to an out-of-bounds write. This could impact system confidentiality, integrity, and availability. Confirming if these IBM systems are in use and exposed is crucial.

CVE advisoryCRITICAL

CVE-2026-16839

IBM AIX and PowerVM VIOS IPv4 Option Parser Integer Underflow Information Disclosure

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in IBM AIX and IBM PowerVM VIOS due to an integer underflow in the IPv4 IP-options parser. This could permit a remote attacker to disclose sensitive information. The potential impact to business operations is uncertain, as it depends on whether affected systems are exposed externally.

CVE advisoryCRITICAL

CVE-2026-16834

IBM AIX and PowerVM VIOS Integer Underflow Denial of Service Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical integer underflow vulnerability exists in IBM AIX and IBM PowerVM VIOS, which could permit a remote attacker to cause a denial of service. This could impact system availability and stability if the affected technologies are reachable.

CVE advisoryCRITICAL

CVE-2026-16822

IBM AIX and PowerVM VIOS TNC Policy Server Certificate Validation Flaw Allows Impersonation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM AIX and PowerVM VIOS have a vulnerability in the TNC policy server due to improper certificate validation. This could allow an attacker to impersonate the server and modify network traffic. It is important to determine if your systems are affected.

CVE advisoryCRITICAL

CVE-2026-70496

Excessive Privileges in search-v2-operator ClusterRole

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in search-v2-operator where its ClusterRole has excessive privileges, allowing it to perform actions equivalent to a cluster administrator. This could enable privilege escalation if an attacker can exploit these broad permissions.

CVE advisoryCRITICAL

CVE-2026-18315

TrueBooker WordPress Plugin Authorization Bypass Leading to Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authorization bypass vulnerability exists in the TrueBooker WordPress plugin, allowing unauthenticated attackers to take over any user account, including administrators. The flaw enables attackers to change a user's email and then initiate a password reset to gain full account control, potentially impacting

CVE advisoryCRITICAL

CVE-2026-72717

Orval Code Generation Vulnerability Allows Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval, a tool for generating code from API specifications, can allow for code execution if a specially crafted default value is included in a schema. This could impact development, testing, or application environments when the generated code is imported. The issue is fixed in version 8.21.0.

CVE advisoryCRITICAL

CVE-2026-72716

Orval Zod Schema Generation Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Orval's Zod schema generation that allows for code execution if specially crafted default values are included in query parameters. This could lead to arbitrary JavaScript evaluation when the generated schema module is imported, impacting developer or CI environments. This issue is fixed in ver

CVE advisoryCRITICAL

CVE-2026-71871

Orval Code Generation Vulnerability Allows JavaScript Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Orval code generation is vulnerable to JavaScript code execution when processing OpenAPI specifications with specially crafted header parameter defaults. This could allow an attacker to inject and run malicious code in developer, CI, or test environments when generated schema modules are imported, impacting the integri

CVE advisoryCRITICAL

CVE-2026-71869

Orval Zod Schema Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval's code generation process could allow for arbitrary JavaScript code execution. This occurs when specially crafted API specifications are processed, leading to the evaluation of malicious code in development or build environments. It is uncertain if Orval is used within the organization.

CVE advisoryCRITICAL

CVE-2026-71868

Orval Zod Code Generation Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Orval's code generation process can allow attackers to execute arbitrary JavaScript if a specially crafted OpenAPI or Swagger specification is processed. This vulnerability affects the zod schema generation when a specially crafted enum default value is included, potentially leading to code execution in developer, CI,

CVE advisoryCRITICAL

CVE-2026-71867

Orval Code Generation Vulnerability Allows JavaScript Evaluation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval's code generation allows for the evaluation of attacker-controlled JavaScript when generated mock factories are used. This occurs due to improper encoding of single quotes in schema property names, potentially leading to code execution in development, testing, or application environments. This

CVE advisoryCRITICAL

CVE-2026-71866

Orval Zod Schema Generation Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A code execution vulnerability exists in Orval, a tool for generating JavaScript clients from API specifications. Improper encoding of schema property names can lead to the evaluation of attacker-controlled JavaScript when generated schema modules are imported, potentially affecting developer, CI, or application enviro

CVE advisoryCRITICAL

CVE-2026-71865

Orval Code Generation Vulnerability Allows JavaScript Evaluation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval code generation allows for JavaScript evaluation if query parameter names are not safely encoded. This could lead to code execution in development, CI, or test environments when generated schema modules are imported. Readers should care if Orval is used, as this impacts the security of their de

CVE advisoryCRITICAL

CVE-2026-71864

Orval Schema Generation Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval, a tool for generating JavaScript clients from API specifications, allows for code execution in developer or build environments. If an attacker controls a header parameter name, their JavaScript can be evaluated when the generated schema module is imported. It is uncertain if Orval is in use or

CVE advisoryCRITICAL

CVE-2026-66794

Multicluster Engine for Kubernetes cluster-proxy-addon Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the Multicluster Engine for Kubernetes `cluster-proxy-addon` allows unauthenticated attackers to bypass security controls and access internal services on managed clusters. By manipulating URL paths, attackers can proxy requests to arbitrary services, potentially leading to unauthorized acces

CVE advisoryCRITICAL

CVE-2026-62682

Orval Code Generation Vulnerability Allows JavaScript Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Orval, a tool for generating JavaScript clients from API specifications, has a vulnerability where an unescaped backtick in server URLs can lead to JavaScript code execution in development or build environments. This occurs when generating clients with specific settings, potentially compromising developer machines or C

CVE advisoryCRITICAL

CVE-2026-62681

Orval Code Generation Vulnerability Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Orval, a tool that generates JavaScript clients, can lead to code execution if an unescaped backtick in an OpenAPI path is processed. This could impact developer, CI, test, or application environments where the generated code is used, resulting in security risks. Uncertainty exists regarding the spec

CVE advisoryCRITICAL

CVE-2026-32475

Elementor Pro Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Elementor Pro permits the upload of malicious files, potentially allowing attackers to gain control of websites. This issue, affecting Elementor Pro, is a concern because the plugin is widely used and often exposed to the public internet. The primary action for readers is to confirm if this technolog

CVE advisoryCRITICAL

CVE-2025-14600

vsDesk Insecure Deserialization Allows Remote Administrative Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access by manipulating application configuration data to authenticate against an arbitrary LDAP server and provision a new administrative account.

CVE advisoryCRITICAL

CVE-2026-75143

FFmpeg RIST Protocol Heap Overflow

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap buffer overflow vulnerability exists in FFmpeg's RIST protocol reader. This issue could allow a remote attacker to trigger the overflow by sending a specially crafted network packet. The impact depends on whether applications use FFmpeg with the RIST protocol via the `async:rist://` URL scheme and are exposed to

CVE advisoryCRITICAL

CVE-2026-71470

Privileged User Can Escalate Privileges via Search Operator Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the search-v2-operator allows a privileged user to manipulate Search Custom Resource fields, potentially injecting arbitrary secrets or replacing container images. This could lead to privilege escalation and cluster compromise. The issue requires a privileged user to exploit and is related to interna

CVE advisoryCRITICAL

CVE-2026-49441

Wazuh Cluster File Path Traversal Vulnerability Allows Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Wazuh platform allows a cluster peer with the shared Fernet key to overwrite critical configuration files, potentially leading to code execution with root privileges. This could occur if the system's `ossec.conf` is replaced and commands are configured to run upon a service reload.

CVE advisoryCRITICAL

CVE-2026-48162

Wazuh Cluster API Path Traversal Allows Private Key Disclosure

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Wazuh's distributed API allows a cluster peer to read sensitive files, including private keys, by exploiting path traversal. This could enable an attacker to forge administrator tokens and gain unauthorized control over the platform. The issue is relevant to Wazuh deployments where cluster communicat

CVE advisoryCRITICAL

CVE-2026-48024

Wazuh cluster path traversal allows remote code execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability exists in Wazuh's cluster synchronization, allowing an authenticated peer with the shared Fernet key to overwrite the `ossec.conf` file. This could lead to the execution of root-level commands when Wazuh services reload, potentially compromising the system. The issue affects Wazuh version

CVE advisoryCRITICAL

CVE-2026-20359

Cisco Crosswork Insufficiently Protected Credentials Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco Crosswork has vulnerabilities related to insufficiently protected credentials. If an attacker can reach the system, they might gain unauthorized access to sensitive information or perform unauthorized actions. This could lead to data compromise and unauthorized control.

CVE advisoryCRITICAL

CVE-2026-20358

Cisco Crosswork External Control of File System Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Cisco Crosswork has a vulnerability allowing external control of the file system, which could lead to system compromise. This issue is relevant if your Cisco Crosswork environment is reachable externally. Confirming exposure is key to understanding potential impacts on system integrity and operational control.

CVE advisoryCRITICAL

CVE-2026-20357

Cisco Crosswork Missing Authentication for Critical Functions Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Cisco Crosswork software has vulnerabilities related to missing authentication for critical functions. If reachable, an unauthenticated attacker could potentially gain unauthorized access or control, impacting the system's confidentiality, integrity, and availability, which could disrupt network management and automati

CVE advisoryCRITICAL

CVE-2026-20318

Cisco Secure Workload Improper Input Validation Vulnerabilities

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Improper input validation vulnerabilities exist in Cisco Secure Workload that could allow an authenticated attacker to cause disruption or unauthorized modification. The potential impact on protected services and system configurations depends on the specific deployment.

CVE advisoryCRITICAL

CVE-2026-20317

Cisco Secure Workload Improper Authentication Vulnerabilities

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Cisco Secure Workload due to improper authentication. If reachable, this issue could allow unauthenticated attackers to impact system integrity and availability. Users should confirm if this platform is deployed in their environment.

CVE advisoryCRITICAL

CVE-2026-20231

Cisco Secure Workload Improper Neutralization Vulnerabilities

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Cisco Secure Workload stems from the improper neutralization of special elements, potentially allowing unauthorized access and impact to confidentiality, integrity, and availability. While not publicly known to be exploited, this issue warrants attention to confirm if the technology is used

CVE advisoryCRITICAL

CVE-2026-20030

Cisco Crosswork SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

SQL injection flaws in Cisco Crosswork software could allow attackers to execute arbitrary SQL commands. If reachable, this could lead to unauthorized access, modification, or deletion of data, and potentially complete system compromise. Confirming deployment and network exposure is crucial for understanding relevance.

CVE advisoryCRITICAL

CVE-2026-62668

Grav API Plugin Webhook Vulnerability Allows Restricted Protocol Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Grav API Plugin allows an authenticated user to retrieve local files or pivot requests to internal services. The plugin improperly validates webhook URLs, enabling attackers to specify restricted protocols. This could lead to unauthorized access to sensitive data or internal system inter

CVE advisoryCRITICAL

CVE-2026-75954

Joomla J-BusinessDirectory SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A SQL injection vulnerability exists in a Joomla extension, potentially allowing attackers to access or alter sensitive data through manipulated search queries. This issue affects public-facing business directory search functions. If reachable, an attacker could inject malicious SQL code.

CVE advisoryCRITICAL

CVE-2026-75949

Joomla Extension J-BusinessDirectory Arbitrary File Upload and Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Joomla extension vulnerability allows unauthenticated attackers to upload or delete arbitrary files via path traversal and weak validation. This could lead to unauthorized modification of website content and potential server compromise. The primary concern is to identify if this extension is in use and assess the res

CVE advisoryCRITICAL

CVE-2026-71960

Cudy WR3000 MQTT Authentication Bypass Via Hard-coded JWT Secret.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A hard-coded secret in Cudy WR3000 routers' MQTT broker authentication plugin allows unauthenticated attackers to forge JWT tokens and gain unauthorized access to the device's mesh networking interface. This vulnerability is reachable by extracting the secret from the firmware image.

CVE advisoryCRITICAL

CVE-2026-53451

Ground Station YAML Injection and Service Hijacking Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Ground Station, a browser-based suite for satellite tracking, has a critical vulnerability allowing unauthenticated attackers to execute code with service privileges and cause persistent crashes by writing a malicious logging configuration. This issue involves directory traversal and affects systems used for satellite

CVE advisoryCRITICAL

CVE-2026-52889

Formie Plugin for Craft CMS Server-Side Template Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Formie Craft CMS plugin is vulnerable to server-side template injection, allowing unauthenticated attackers to execute arbitrary code by submitting specially crafted data through public forms. This can lead to the disclosure of sensitive information, modification of application state, or remote code execution, impa

CVE advisoryCRITICAL

CVE-2026-47187

SSHFS Path Traversal Vulnerability Allows Local File Disclosure and Modification.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in SSHFS allows a malicious SFTP server to trick the client into resolving symbolic links that point to local files. This can result in the disclosure of readable local files or the modification of local files with server-controlled content. This could impact systems that use SSHFS to connect to SSH ser

CVE advisoryCRITICAL

CVE-2026-45272

MyBooks Web Server Code Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the MyBooks ebook management web server allows an administrator to inject and execute arbitrary Python code by submitting a crafted key name. This could lead to unauthorized command execution with service account privileges, potentially affecting system data and causing service disruption. C

CVE advisoryCRITICAL

CVE-2026-16656

IBM AIX and PowerVM VIOS Improper Authentication Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in IBM AIX and PowerVM VIOS could allow an unauthenticated attacker to gain root privileges. If these systems are reachable on a network, an attacker could potentially achieve complete system control, impacting availability, integrity, and confidentiality. Confirmation of system relevance and exposure w

CVE advisoryCRITICAL

CVE-2026-15068

IBM AIX and PowerVM VIOS NIM Command Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in IBM AIX and PowerVM VIOS NIM that could allow an authenticated attacker to execute arbitrary commands. This impacts systems used for operating system provisioning and management. While typically deployed in restricted networks, if reachable, this could lead to unauthorized system cont

CVE advisoryCRITICAL

CVE-2026-15065

IBM AIX and PowerVM VIOS Intermediate Certificate Authority Private Key Exposure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

IBM AIX and PowerVM VIOS are affected by a vulnerability where intermediate certificate authority private keys were exposed in a publicly available update file. This exposure could allow a remote attacker to bypass security restrictions, potentially impacting systems that rely on these keys for secure communication or

CVE advisoryCRITICAL

CVE-2026-76244

stigmem-node Federation Traffic Exposed by Insecure Default Configuration

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An insecure configuration in stigmem-node allows federation traffic to traverse networks without strong protection if non-loopback endpoints are enabled and mutual TLS is disabled. This could expose sensitive communications to interception and man-in-the-middle attacks, warranting a review of specific network configura

CVE advisoryCRITICAL

CVE-2026-76243

Stigmem Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in stigmem allows unauthenticated access to read, write, and federation operations when authentication is disabled on externally exposed deployments. This could enable anonymous users to perform sensitive operations on your data. Confirm if stigmem is in use and exposed in your environment.

CVE advisoryCRITICAL

CVE-2026-76242

Stigmem Federation Peer Registration Authentication Bypass.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in stigmem-node allows an attacker to register a malicious federation peer without administrator verification, potentially enabling unauthorized access to or tampering with federation traffic. This impacts nodes accepting federation peer registration over a network where the initial process can be inter

CVE advisoryCRITICAL

CVE-2026-76214

phpMyFAQ WebAuthn Authentication Bypass via Replay Attack

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in phpMyFAQ's WebAuthn login can allow an attacker to replay a captured login assertion, granting persistent access without user interaction or hardware key. This bypasses authentication, enabling unauthorized account access. Readers should care because it affects user authentication and unauthorized ac

CVE advisoryCRITICAL

CVE-2026-76213

phpMyFAQ 2FA Brute-Force Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in phpMyFAQ's two-factor authentication allows bypassing security limits by resetting the attempt counter through session manipulation. This could enable brute-force guessing of authentication codes for web-based FAQ applications, which are often publicly accessible. It is uncertain if this specific vul

CVE advisoryCRITICAL

CVE-2026-74804

Joomla Zoo Extension Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a Joomla extension, allowing attackers to manipulate database queries. This could lead to unauthorized access or modification of sensitive data. The primary concern is confirming the use and internet exposure of this extension.

CVE advisoryCRITICAL

CVE-2026-74803

Joomla Zoo Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated arbitrary file uploads, potentially leading to system compromise. This flaw in the image element is reachable via the public internet, enabling attackers to upload any file type by manipulating the Content-Type. This could result in unauthorized acce

CVE advisoryCRITICAL

CVE-2026-16019

FAYDAM Datalogger SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in FAYDAM Datalogger allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation. This critical issue, affecting versions prior to 2.8.0, could impact database integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-73391

Total Donations Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a donation plugin, allowing an attacker to access or modify database information. This flaw could expose sensitive donation data if the plugin is publicly accessible. Readers should verify if this plugin is in use to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-73390

Total Donations Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Total Donations allows unauthenticated privilege escalation, potentially enabling attackers to gain elevated access to affected systems without credentials. This could impact the integrity and confidentiality of operations if the software is in use and reachable. Ascertaining usage is crucia

CVE advisoryCRITICAL

CVE-2026-73389

Kalles Addons PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in Kalles Addons, potentially allowing attackers to execute arbitrary code. This affects internet-facing web applications using the plugin. It is important to identify instances of the plugin and assess their exposure and criticality.

CVE advisoryCRITICAL

CVE-2026-73388

Nikstore Core Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in Nikstore Core that allows unauthenticated attackers to access or manipulate sensitive data. This vulnerability could impact data integrity and service availability for internet-facing applications using this technology. Determining if Nikstore Core is in use and assessin

CVE advisoryCRITICAL

CVE-2026-73364

Flexible Subscriptions PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A PHP Object Injection vulnerability exists in the Flexible Subscriptions plugin. If reachable, an unauthenticated attacker could inject malicious PHP objects, potentially leading to arbitrary code execution and system compromise. Confirmation is needed on whether this plugin is used within the environment.

CVE advisoryCRITICAL

CVE-2026-73347

TrueBooker Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in TrueBooker booking software could allow unauthenticated attackers to gain elevated privileges, potentially leading to system compromise. It's important to determine if this technology is in use and assess its exposure to understand potential risks.

CVE advisoryCRITICAL

CVE-2026-73185

NGG Smart Image Search Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in NGG Smart Image Search, potentially allowing attackers to access or manipulate database information via network requests. This could lead to data exposure or service disruption. Confirming the presence and reachability of this technology is important to assess yo

CVE advisoryCRITICAL

CVE-2026-73183

SQL Injection in Maps Marker Pro Versions Prior to 4.33

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Maps Marker Pro plugin, potentially allowing attackers to access or disrupt sensitive database information. This issue is relevant if the plugin is active and accessible over the network, posing a risk to data integrity and service availability.

CVE advisoryCRITICAL

CVE-2026-67364

Joomla Balbooa Forms Unauthenticated PHP Code Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP code injection vulnerability exists in a Joomla form extension, allowing unauthenticated attackers to execute arbitrary server-side code. This can occur if a form is configured with a custom PHP handler and uses a specific shortcode, potentially leading to a website compromise.

CVE advisoryCRITICAL

CVE-2026-66613

JetEngine Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in JetEngine, allowing unauthenticated remote code execution over the network, potentially leading to system compromise. It's important to determine if this technology is in use and exposed within the environment to understand potential risks.

CVE advisoryCRITICAL

CVE-2026-19490

NetScaler ADC and Gateway Vulnerability Allows Network Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in NetScaler ADC and NetScaler Gateway, potentially impacting confidentiality, integrity, and availability. If reachable, an attacker could exploit this over the network without authentication or user interaction, leading to system compromise. Understanding the scope and exposure of your

CVE advisoryCRITICAL

CVE-2026-18937

Broken Link Checker WordPress Plugin Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Broken Link Checker WordPress plugin may allow unauthenticated code execution if plain permalinks are active. This could lead to server compromise. The relevance and exposure of this plugin in our environments needs confirmation.

CVE advisoryCRITICAL

CVE-2026-18776

TrueBooker WordPress Plugin Account Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the TrueBooker WordPress plugin allows unauthenticated users to change arbitrary user email addresses, enabling account takeover via password resets. This issue stems from improper authorization checks in the plugin's AJAX actions.

CVE advisoryCRITICAL

CVE-2026-18031

TabaPay Gateway WordPress Plugin Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The TabaPay Gateway WordPress plugin has a critical authentication bypass vulnerability. Unauthenticated attackers can log in as any user, including administrators, by sending a manipulated payment callback request. This could compromise user accounts and administrative control if the plugin is used and reachable.

CVE advisoryCRITICAL

CVE-2026-76008

Comfast CF-N1-S URI Parameter Parsing Stack Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a network device's configuration interface, specifically within the URI parameter parsing function, due to a stack-based buffer overflow. This flaw allows remote attackers to potentially compromise the device by manipulating input parameters. This issue is relevant because it affects

CVE advisoryCRITICAL

CVE-2026-11751

Armeria-xds TLS Peer Verification Bypass Allows Man-in-the-Middle Attacks

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Armeria-xDS where upstream TLS peer verification can be bypassed, potentially enabling man-in-the-middle attacks on xDS-managed connections. This could allow attackers to intercept or manipulate internal service communications.