NVD disclosure day

Published threat advisories for August 20, 2026

CVE advisoryCRITICAL

CVE-2026-77647

SPIP Arbitrary Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

SPIP, a content management system, has a critical vulnerability allowing unauthenticated remote code execution. This issue, related to incorrect identification of PHP code blocks and mishandling of specific characters by `var_export`, has been exploited in the wild. As SPIP is often a public-facing web application, thi

CVE advisoryCRITICAL

CVE-2026-77645

PTC Windchill and FlexPLM Untrusted Data Deserialization RCE.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical remote code execution vulnerability exists in PTC Windchill and PTC FlexPLM due to the deserialization of untrusted data. If reachable, this could allow an attacker to execute arbitrary code on affected systems, potentially compromising their integrity and availability.

CVE advisoryCRITICAL

CVE-2026-77644

PTC Windchill WRR Enterprise Access Control Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical access control bypass vulnerability exists in PTC Windchill Risk and Reliability Enterprise Edition, which could allow unauthorized access. Understanding the system's deployment and exposure is key to assessing potential risks to sensitive data or system integrity.

CVE advisoryCRITICAL

CVE-2026-72843

EverShop Customer Update Route Vulnerability Allows Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in EverShop's customer update route allows attackers to take over customer accounts by modifying email addresses and passwords. This could lead to account lockout and unauthorized access. The issue is reachable via network and poses a risk to customer data and platform integrity.

CVE advisoryCRITICAL

CVE-2026-69851

Azure Active Directory SSRF Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical server-side request forgery vulnerability exists in Azure Active Directory, potentially allowing an authorized attacker to elevate privileges over a network. This could impact system integrity by enabling unauthorized actions. Readers should care because Azure Active Directory is a core identity provider tha

CVE advisoryCRITICAL

CVE-2026-69555

Azure Arc Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization flaw in Azure Arc, a hybrid cloud management platform, allows an unauthenticated network attacker to elevate privileges. This could lead to unauthorized control over managed resources. Confirm if your Azure Arc deployment is reachable and potentially affected.

CVE advisoryCRITICAL

CVE-2026-69400

Azure Logic Apps Path Traversal Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. This issue stems from an improper limitation of a pathname to a restricted directory. If reachable, this could potentially impact system data and service behavior, and readers should care due to the

CVE advisoryCRITICAL

CVE-2026-68789

Azure SQL Database SQL Injection Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An SQL injection vulnerability in Azure SQL Database allows an authorized attacker to elevate privileges over a network by improperly neutralizing special elements in SQL commands. This could lead to unauthorized access and control over sensitive data and database services. Understanding specific deployment and access

CVE advisoryCRITICAL

CVE-2026-68782

Azure SQL Database SQL Injection Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Azure SQL Database has an SQL injection vulnerability where improper handling of commands allows an authorized network attacker to elevate privileges. This is a concern if your Azure SQL Database is reachable and the service is in use, as it could lead to unauthorized control.

CVE advisoryCRITICAL

CVE-2026-66309

Azure SQL Database Privilege Escalation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper access control vulnerability in Azure SQL Database could allow an authenticated attacker to elevate privileges over a network. This may impact the confidentiality, integrity, and availability of the database. Confirming network exposure and business criticality is important to understand the relevance of th

CVE advisoryCRITICAL

CVE-2026-65816

Azure Arc Privilege Escalation via Incorrect Name Resolution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Azure Arc, which manages resources across cloud and on-premises environments, could allow an attacker to elevate privileges over a network. This means unauthorized users could gain elevated control of systems. It is important to confirm if your Azure Arc deployments are reachable and assess

CVE advisoryCRITICAL

CVE-2026-65801

Microsoft Exchange Online SSRF Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical Server-Side Request Forgery vulnerability in Microsoft Exchange Online could allow an unauthorized attacker to elevate privileges over a network. This impacts a critical, internet-facing business communication service. Confirming relevance and potential exposure within our environment is important to underst

CVE advisoryCRITICAL

CVE-2026-65770

Azure Managed Instance for Apache Cassandra Argument Injection Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Azure Managed Instance for Apache Cassandra that allows unauthorized network-based command argument injection, potentially leading to remote code execution. This impacts a managed database service and could affect confidentiality, integrity, and availability if an instance is reachabl

CVE advisoryCRITICAL

CVE-2026-63509

Microsoft Fabric Privilege Escalation via Relative Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A relative path traversal vulnerability in Microsoft Fabric could allow an authenticated attacker to elevate privileges over a network. This could lead to unauthorized access and control, impacting system data and services. It is important to identify affected instances and plan for remediation.

CVE advisoryCRITICAL

CVE-2026-62834

Azure Data Factory Signature Verification Flaw Enables Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper cryptographic signature verification in Azure Data Factory allows an attacker to elevate privileges over a network. This could grant unauthorized access and control within the service, impacting data integration workflows. It is important to determine if your organization uses this service to assess potenti

CVE advisoryCRITICAL

CVE-2026-55769

CloudNativePG Superuser Access Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in CloudNativePG, affecting its management of PostgreSQL databases in Kubernetes. An attacker with database owner privileges could gain PostgreSQL superuser access, potentially enabling operating system command execution and access to sensitive credentials. The reachability and business

CVE advisoryCRITICAL

CVE-2026-18835

IBM AIX and PowerVM VIOS Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical command injection vulnerability affects IBM AIX and IBM PowerVM VIOS, allowing authenticated attackers to execute arbitrary commands. This occurs due to improper neutralization of special elements in OS commands. If reachable, an attacker could compromise the affected systems.

CVE advisoryCRITICAL

CVE-2026-17160

IBM AIX and PowerVM VIOS Integer Overflow Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in IBM AIX and IBM PowerVM VIOS allows remote attackers to execute arbitrary code due to an integer overflow. This could lead to a compromise of system integrity and availability if reachable. Customers should identify affected systems and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-17152

IBM AIX and PowerVM VIOS Buffer Overflow Executes Arbitrary Code

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical buffer overflow vulnerability exists in IBM AIX and IBM PowerVM VIOS that could permit an unauthenticated remote attacker to execute arbitrary code, potentially leading to system compromise. Uncertainty remains regarding the specific versions affected and whether exploitation is actively occurring.

CVE advisoryCRITICAL

CVE-2026-17145

IBM AIX and PowerVM VIOS Improper Privilege Management Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM AIX and PowerVM VIOS have a critical vulnerability due to improper privilege management, potentially allowing remote code execution. If these systems are network-reachable, an attacker could exploit this flaw to gain unauthorized control and impact system resources. Confirmation of product usage and an assessment o

CVE advisoryCRITICAL

CVE-2026-17142

IBM AIX and PowerVM VIOS Improper Authentication Command Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in IBM AIX and IBM PowerVM VIOS allows unauthenticated remote attackers to execute arbitrary commands due to improper authentication. If reachable, this could lead to a compromise of system confidentiality, integrity, and availability. Confirm if these IBM products are deployed and assess poten

CVE advisoryCRITICAL

CVE-2026-17136

IBM AIX and PowerVM VIOS Format String Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A format string vulnerability in IBM AIX and IBM PowerVM VIOS could allow remote attackers to execute arbitrary code. This vulnerability is reachable over the network without authentication or user interaction. The potential impact includes compromise of system integrity and availability.

CVE advisoryCRITICAL

CVE-2026-17122

IBM AIX and PowerVM VIOS Stack Buffer Overflow Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack-based buffer overflow in IBM AIX and IBM PowerVM VIOS could allow an unauthenticated remote attacker to execute arbitrary code. This could lead to system compromise. Organizations should verify if these technologies are in use and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-17118

IBM AIX and PowerVM Use-After-Free Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in IBM AIX and IBM PowerVM VIOS could allow a remote attacker to execute arbitrary code without authentication. This threat could lead to unauthorized command execution on affected systems if they are reachable. It is important to confirm the presence and exposure of these systems within

CVE advisoryCRITICAL

CVE-2026-17040

IBM AIX and PowerVM VIOS Buffer Overflow Executes Arbitrary Code

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A buffer overflow vulnerability in IBM AIX and IBM PowerVM VIOS could permit an unauthenticated, remote attacker to execute arbitrary code. This means an attacker could potentially gain control of the affected systems. Organizations should identify if these IBM products are in use and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-71485

Centrifugo Header Spoofing Allows Unauthorized Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Centrifugo, a real-time messaging server, has a vulnerability allowing remote clients to spoof trusted headers. This could lead to unauthorized access if backend systems rely on these headers for authentication or authorization, impacting real-time messaging services.

CVE advisoryCRITICAL

CVE-2026-67567

Multicloud-Operators-Subscription HelmRelease Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in the multicloud-operators-subscription component allows authenticated tenants to bypass security controls. This flaw enables the deployment of arbitrary resources cluster-wide, potentially leading to a complete security compromise.

CVE advisoryCRITICAL

CVE-2026-66788

Lighthouse Resource Injection Vulnerability Allows Cross-Cluster Compromise

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Lighthouse allows an attacker with access to a spoke cluster to inject unauthorized resources into any namespace on peer clusters. This could lead to privilege escalation or system compromise by manipulating broker objects. The issue impacts cross-cluster communication and critical system na

CVE advisoryCRITICAL

CVE-2026-66785

Submariner Endpoint Spoofing Allows Network Traffic Redirection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Submariner permits a malicious cluster to redirect network traffic from other connected clusters by publishing a crafted network endpoint. This can occur because the system fails to validate network subnets, allowing an attacker to specify arbitrary ranges. Consequently, traffic intended for these ranges may

CVE advisoryCRITICAL

CVE-2026-19586

Omada Gateway OpenVPN Server Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A pre-authentication OS command injection vulnerability exists in Omada gateways configured as OpenVPN servers due to insufficient validation of client-supplied data. An unauthenticated remote attacker could exploit this to execute arbitrary commands, potentially leading to full compromise of the affected device if the

CVE advisoryCRITICAL

CVE-2026-73257

Mongoose HTTP Desynchronization Request Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Mongoose web server and network library allows remote attackers to inject requests by sending a crafted HTTP request. This can lead to unauthorized access or modification of resources due to a desynchronization in how HTTP headers are parsed. This is relevant because Mongoose is often integrated

CVE advisoryCRITICAL

CVE-2026-73256

Mongoose HTTP Request Smuggling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Mongoose embedded web server library allows unauthenticated attackers to smuggle HTTP requests. When Mongoose is deployed as an HTTP/1.0 reverse proxy, specially crafted requests can bypass security controls, potentially leading to unauthorized access or state changes. This issue is relevant when

CVE advisoryCRITICAL

CVE-2026-73253

Mongoose TLS Certificate Verification Bypass Allows Impersonation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Mongoose's TLS stack could allow an on-path network attacker to impersonate subdomains by exploiting wildcard certificate matching logic. This bypass could permit the interception and modification of TLS traffic. This issue is relevant if Mongoose is used in deployments handling TLS connections and i

CVE advisoryCRITICAL

CVE-2026-73251

Mongoose TLS Impersonation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Mongoose embedded web server and network library allows a network attacker to impersonate a TLS server to Mongoose clients. This could lead to interception of sensitive data, credential disclosure, traffic modification, or malicious responses by enabling the acceptance of forged certificates.

CVE advisoryCRITICAL

CVE-2026-63385

Libevent HTTP Parsing Weaknesses Allow Header Injection and Path Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Libevent, a network I/O library, has HTTP parsing weaknesses that could allow attackers to bypass validation or inject headers. This may lead to unauthorized access or altered request interpretations if the vulnerable parsing logic is exposed to network traffic. Confirming Libevent's use and exposure in your environmen

CVE advisoryCRITICAL

CVE-2026-63382

Libevent HTTP Parser Desynchronization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Libevent networking library that could allow an unauthenticated remote attacker to desynchronize request boundaries. This may enable attackers to smuggle a second request, potentially bypassing access controls or poisoning caches when Libevent is deployed behind a proxy. The core issue lie

CVE advisoryCRITICAL

CVE-2026-53424

Samly Authentication Bypass via Replay of SAML Assertions

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Samly library has an authentication bypass vulnerability that allows attackers to impersonate users by replaying captured SAML assertions. This happens because the library does not enforce the rule that each assertion should only be used once, potentially granting unauthorized access to systems.

CVE advisoryCRITICAL

CVE-2026-2334

vsDesk CSV Import Arbitrary File Upload Leading to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker with administrative privileges can bypass client-side file validation in vsDesk's "Import via CSV" component, potentially allowing arbitrary file uploads and leading to remote code execution. This is a critical vulnerability that impacts the web application's integrity and availability if admi

CVE advisoryCRITICAL

CVE-2026-71428

Unstructured URL Fetching Vulnerability Allows Internal Data Disclosure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The unstructured library, used for pre-processing images and documents, has a vulnerability where it fetches URLs without host validation. This allows an attacker to craft URLs that could lead to internal data disclosure or trigger unintended actions on internal services. Readers should care because this could expose s

CVE advisoryCRITICAL

CVE-2026-55642

dbx Remote SQL Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the dbx database client software, allowing unauthenticated network attackers to execute arbitrary SQL commands. This could lead to the disclosure, modification, or destruction of data in connected databases. The issue arises from a flaw in authentication handling when a password is not configu

CVE advisoryCRITICAL

CVE-2026-16926

IBM AIX and PowerVM VIOS Arbitrary File Overwrite Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in IBM AIX and IBM PowerVM VIOS that allows a remote attacker to overwrite arbitrary files. This input handling flaw could lead to system compromise if targeted. It is important to determine if these systems are used and exposed within the environment.

CVE advisoryCRITICAL

CVE-2026-15706

Baylan Smart Meter Management Application Authentication Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass vulnerability exists in the Baylan Smart Meter Management Application (BMS). Attackers can access critical functions without logging in, potentially impacting meter data integrity and availability. Confirming this application's relevance and exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-28164

Easy Elementor Addons Cross-Site Request Forgery Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Cross-Site Request Forgery vulnerability in the Easy Elementor Addons plugin could allow an attacker to trick users into performing unintended actions on a website. This might lead to unauthorized changes to website content or settings if a user visits a malicious site or link. Uncertainty exists regarding specific p

CVE advisoryCRITICAL

CVE-2026-74018

Warehouse Cargo Subscriber Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Warehouse Cargo theme allows unauthorized file uploads, potentially leading to system compromise. This issue, affecting public-facing website interfaces, requires confirmation of the theme's use and exposure to the internet. The primary concern is understanding if the vulnerable software

CVE advisoryCRITICAL

CVE-2026-74016

Smart Cleaning Theme Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Smart Cleaning, allowing authenticated users to upload arbitrary files. This could enable attackers to compromise a site by uploading malicious code. It is important to determine if this technology is used and reachable within your environment.

CVE advisoryCRITICAL

CVE-2026-74014

IT Residence Arbitrary File Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file upload vulnerability exists in the IT Residence theme, allowing authenticated users to upload malicious files. This could lead to arbitrary code execution and system compromise. The risk is amplified as WordPress themes are typically public-facing.

CVE advisoryCRITICAL

CVE-2026-74001

User Registration & Membership Pro Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical broken authentication vulnerability exists in a user registration and membership plugin, potentially allowing unauthenticated attackers to gain unauthorized access to user accounts and administrative control. This issue impacts how user verification is handled, and if reachable, could lead to compromised use

CVE advisoryCRITICAL

CVE-2026-73992

Query Wrangler Subscriber RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the Query Wrangler component of web applications. If reachable, an attacker with subscriber privileges could exploit this flaw to execute arbitrary code on the server, potentially compromising the application and its data, necessitating confirmation of its use an

CVE advisoryCRITICAL

CVE-2026-68566

BookingPress Appointment Booking Pro SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the BookingPress Appointment Booking Pro plugin. Attackers can exploit this flaw to inject malicious code, potentially leading to unauthorized access to sensitive booking and customer data. This is a concern for public-facing applications using the plugin.

CVE advisoryCRITICAL

CVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Abandoned Cart Pro for WooCommerce plugin, allowing unauthenticated attackers to escalate privileges. If reachable, this could lead to unauthorized administrative access, potentially impacting e-commerce operations and sensitive data. Confirmation of the plugin's presence and expo

CVE advisoryCRITICAL

CVE-2026-66680

Locatoraid Store Locator SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Locatoraid Store Locator plugin, potentially allowing attackers to access sensitive data from the application's database. The vulnerability is network-accessible and does not require user interaction. It is important to confirm if this plugin is in use and ex

CVE advisoryCRITICAL

CVE-2026-66649

Directory Pro SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Directory Pro, a WordPress plugin, which could allow attackers to access or modify sensitive data. This issue is reachable via unauthenticated network requests and could lead to unauthorized data disclosure or denial of service. Confirming the use and exposure of

CVE advisoryCRITICAL

CVE-2026-66609

TheGem Elementor Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in TheGem theme for Elementor allows attackers to access sensitive database information. This external-facing issue can be triggered through crafted network requests, potentially leading to data disclosure or service disruption. It is important to determine if your organiz

CVE advisoryCRITICAL

CVE-2026-66600

Media Library Assistant Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Media Library Assistant plugin, allowing authenticated users to upload arbitrary files. This could enable attackers to execute malicious code, potentially compromising the affected system. Confirmation of the plugin's presence and reachability is necessary to assess the risk.

CVE advisoryCRITICAL

CVE-2026-66593

CleanTalk Security Scan Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Security & Malware scan by CleanTalk plugin. This could allow attackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive data or disruption of service. The vulnerability is reachable via network requests and does not requi

CVE advisoryCRITICAL

CVE-2026-66592

rtMedia for WordPress Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the rtMedia plugin for WordPress, potentially allowing attackers to access or manipulate sensitive database information. This is a concern for application owners and infrastructure teams responsible for web services. The impact depends on database structure and p

CVE advisoryCRITICAL

CVE-2026-66583

Forminator Plugin PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Forminator plugin, potentially allowing attackers to execute arbitrary code. If reachable, this could compromise server confidentiality, integrity, and availability. Confirming plugin usage and assessing exposure is crucial for affected systems.

CVE advisoryCRITICAL

CVE-2025-15689

Capella Theme Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the Capella technology, potentially allowing unauthorized users to gain elevated access without credentials. If reachable, this could lead to unauthorized system control and data modification, impacting system security and data integrity. Confirming the pr

CVE advisoryCRITICAL

CVE-2025-15688

Unauthenticated SQL Injection in Capella Versions 2.5.5 and Earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Capella, allowing network-accessible exploitation. If reached, an attacker could access or manipulate database information. This is relevant for protecting sensitive system data and confirming usage and exposure.

CVE advisoryCRITICAL

CVE-2026-13097

FreeIPA Kerberos Principal Impersonation Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A privilege escalation flaw in FreeIPA allows an authenticated user with LDAP write privileges to impersonate privileged service accounts by creating equivalent Kerberos principal names. This could lead to unauthorized acquisition of Kerberos tickets for sensitive services, potentially resulting in full domain compromi

CVE advisoryCRITICAL

CVE-2026-11861

FreeIPA Trust Bypass Allows Active Directory User Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in FreeIPA allows authenticated Active Directory users to bypass authentication for services by impersonating client names in the Ticket Granting Service. This could lead to privilege escalation within the FreeIPA domain if a trust relationship is configured. The issue stems from FreeIPA services not ve

CVE advisoryCRITICAL

CVE-2026-14950

FDS Web Interface Session Expiration Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker with a valid session identifier can maintain access to the FDS web interface after the session should have expired. This vulnerability increases risks from stolen or leaked sessions, potentially allowing unauthorized continued access.

CVE advisoryCRITICAL

CVE-2026-75860

WordPress JSON Options Plugin Privilege Escalation Leading to Site Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The JSON Options WordPress plugin has a critical vulnerability that allows unauthenticated users to modify arbitrary site settings. This could lead to privilege escalation, enabling user registration and setting default roles to administrator, potentially resulting in full site takeover. The issue is externally exposed