NVD disclosure day

Published threat advisories for August 22, 2026

CVE advisoryCRITICAL

CVE-2026-74730

Linux Kernel NFS Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in the Linux kernel's NFS client can be triggered by a delayed state ID free operation. If exploited, this could lead to system instability or unauthorized data access. This vulnerability is network-accessible and could impact the integrity and availability of NFS services.

CVE advisoryCRITICAL

CVE-2026-74723

Linux Kernel Btrfs LZO Inline Extent Header Validation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's btrfs file system may allow a specially crafted file to cause a kernel memory read beyond boundaries when processed. This could lead to system instability or crashes. The issue requires local file system access to be triggered.

CVE advisoryCRITICAL

CVE-2026-74705

Linux Kernel UDP Tunnel Segmentation Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's UDP tunnel segmentation can cause a use-after-free error when processing network packets. This may lead to system instability or unauthorized access if reachable. The uncertainty is whether this specific kernel function is in use within the environment.

CVE advisoryCRITICAL

CVE-2026-74688

Linux Kernel SCTP Use-After-Free Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the Linux kernel's SCTP implementation could allow a use-after-free error, potentially leading to system instability or code execution if a queued control chunk's transport is removed. This issue arises from improperly managed transport pointers during chunk transmission, where a stale point

CVE advisoryCRITICAL

CVE-2026-74669

Linux Kernel IPVS Stack Out-of-Bounds Write.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's IPVS component could allow unauthorized memory writes. This occurs when processing specific ICMP errors in tunnel configurations, potentially leading to system instability. The advisory does not indicate direct exposure of sensitive user data.

CVE advisoryCRITICAL

CVE-2026-74628

Linux Kernel net/x25 Use-After-Free Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel has a use-after-free vulnerability in its X.25 networking component due to improper timer management. This could allow a timer to access freed memory, potentially leading to system instability or crashes. While classified as critical, the rarity of X.25 protocol usage in modern systems limits its broad

CVE advisoryCRITICAL

CVE-2026-74617

Linux Kernel DIBs Lock Initialization Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Linux kernel where a device driver lock may not be initialized before it's accessed during interrupt handling. This could potentially lead to system instability or compromise if reachable, though it is not expected to be externally exploitable.

CVE advisoryCRITICAL

CVE-2026-74616

Linux Kernel XDP Clone Memory Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's XDP networking component can allow cloned packet data to corrupt memory and metadata. This occurs when the kernel mishandles memory allocation for cloned packets, potentially impacting kernel integrity and system stability. The exact exposure and impact depend on how the affected k

CVE advisoryCRITICAL

CVE-2026-74612

Linux veth skb length accounting vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Linux kernel vulnerability exists in the virtual Ethernet (veth) driver that may improperly handle network data fragments. This could lead to the disclosure of kernel memory or corrupted data if a specially crafted network packet targets the veth driver's XDP fragment adjustments. This impacts internal data integrity

CVE advisoryCRITICAL

CVE-2026-74611

Linux Kernel TLS RX Iterator Advancement Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's TLS decryption could allow an attacker to corrupt data by manipulating TLS 1.3 optimistic retries. This could lead to data integrity issues and potentially unauthorized data modification. The relevance depends on specific TLS configurations and exposure to malicious network traffic

CVE advisoryCRITICAL

CVE-2026-74608

Linux Kernel smb Client Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the Linux kernel's CIFS client. This could allow an attacker to cause memory corruption by exploiting a race condition during network interface refreshes and channel creation. If reachable, this may lead to system instability or data corruption.

CVE advisoryCRITICAL

CVE-2026-74597

Linux Kernel IPv6 Tunneling Vulnerability Corrupts Shared Memory

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's IPv6 tunneling can lead to memory corruption when handling ICMP error messages. This could potentially cause system instability or compromise if an attacker sends specially crafted packets to a system with IPv6 tunneling enabled. The exact impact and exploitability depend on specif

CVE advisoryCRITICAL

CVE-2026-74591

Linux Kernel Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's memory management could allow an attacker to corrupt memory indexing under specific race conditions involving memory allocation failures and retries. This could lead to system instability, SIGILL and SIGSEGV errors, or incorrect placement of executable code. The issue is considered

CVE advisoryCRITICAL

CVE-2026-74588

Linux Kernel SCTP Use-After-Free Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation could allow for memory corruption. This occurs when a chunk's transport pointer is not updated correctly during list moves. If triggered by a peer, this could lead to a use-after-free error, potentially causing system insta

CVE advisoryCRITICAL

CVE-2026-74587

Linux Kernel SCTP Use-After-Free Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's SCTP module involves a use-after-free flaw in handling ASCONF chunks during peer restarts. If reachable, this could lead to system instability or unauthorized access by an attacker. Confirmation of the use and exposure of this kernel functionality is recommended.

CVE advisoryCRITICAL

CVE-2026-74586

Linux Kernel SCTP Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's SCTP component may allow an authenticated remote attacker to cause a use-after-free condition. This could lead to system instability or unexpected behavior. The issue stems from how the kernel handles transport connections during SCTP association configuration. Confirming if your L

CVE advisoryCRITICAL

CVE-2026-4703

WS Form LITE WordPress Plugin PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A PHP Object Injection vulnerability in the WS Form LITE WordPress plugin allows unauthenticated attackers to inject PHP objects via form submissions. Exploitation requires an additional vulnerable component with a POP chain, potentially leading to file deletion, data retrieval, or code execution. The relevance of this

CVE advisoryCRITICAL

CVE-2026-77992

Joomla Fabrik Component Heredoc Terminator Breakout Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension due to an unchecked endpoint, potentially allowing unauthenticated attackers to manipulate calculations. This issue, related to a heredoc terminator breakout, could lead to unauthorized actions or data manipulation if the affected component is exposed. The full impa

CVE advisoryCRITICAL

CVE-2026-76607

Joomla Fabrik Download Element Missing ACL Check Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension, allowing unauthenticated attackers to potentially access sensitive information or system functions via its download element. Confirmation of the extension's presence and usage within the organization is crucial to understand and address any potential risk to system

CVE advisoryCRITICAL

CVE-2026-76606

Joomla Fabrik Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical path traversal vulnerability exists in a Joomla extension, allowing unauthenticated attackers to access sensitive server files via crafted image element requests. This could lead to unauthorized data exposure and system compromise. Confirming the presence and reachability of this extension within our environ

CVE advisoryCRITICAL

CVE-2026-76605

Joomla Fabrik Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in a Joomla extension, potentially allowing unauthenticated attackers to run arbitrary code. This impacts the integrity and availability of affected websites and their servers. The primary concern is confirming if this extension is in use and exposed to the internet

CVE advisoryCRITICAL

CVE-2026-76604

Joomla Fabrik PHP Element Unauthenticated Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in a Joomla extension allows unauthenticated remote code execution via its PHP form element, potentially leading to unauthorized control or service disruption. The issue is relevant if the extension is in use and exposed to external access.

CVE advisoryCRITICAL

CVE-2026-76602

Joomla Fabrik Unauthenticated SQL Injection in List Order By < 4.7.3

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla extension affecting how data lists are ordered, potentially allowing unauthenticated attackers to inject SQL code. This could lead to unauthorized access to sensitive database information. Confirming usage and exposure within our environment is necessary.

CVE advisoryCRITICAL

CVE-2026-76571

Joomla Fabrik Extension Unauthenticated SQL Injection Allows Full Database Read

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a Joomla extension, enabling attackers to read the entire database. This occurs when the list filter's condition parameter is directly incorporated into SQL queries without proper sanitization. This could lead to a full database compromise.

CVE advisoryCRITICAL

CVE-2026-63310

NLTK Downloader Integrity Verification Weakness.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the NLTK downloader module, allowing attackers to inject malicious code by intercepting package downloads. This could lead to arbitrary code execution on affected systems if malicious packages are extracted without validation. Readers should care because this impacts development environments a

CVE advisoryCRITICAL

CVE-2026-75870

Perl Punk Session Cookie Forgery Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Perl's Punk session management allows attackers to forge session cookies by exploiting a missing secret configuration. This could enable unauthorized access or privilege escalation by impersonating users. The issue stems from a default empty HMAC key, enabling offline cookie manipulation.

CVE advisoryCRITICAL

CVE-2026-77946

TRENDnet TEW-821DAP NTP Timezone Configuration Stack Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote stack-based buffer overflow vulnerability exists in a TRENDnet network device's NTP Timezone Configuration Handler. Exploitation could lead to system compromise, with a public exploit available. This issue warrants attention for network infrastructure security.

CVE advisoryCRITICAL

CVE-2026-78003

Mailgun for WordPress Plugin Path Traversal and SSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Mailgun for WordPress plugin that could allow unauthenticated attackers to intercept sensitive information, potentially leading to account takeover. The flaw stems from insufficient input validation within the plugin's functions. If an attacker can reach this vulnerability, they might be a

CVE advisoryCRITICAL

CVE-2026-12710

Google Cloud Integration QueryEngineTask Missing Authorization Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical missing authorization vulnerability in Google Cloud Application Integration's QueryEngineTask could permit an external attacker to access sensitive internal data. This issue, affecting specific versions, has been patched, and no customer action is required.

CVE advisoryCRITICAL

CVE-2026-77002

SmilePass Selfie Login WordPress Plugin Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the SmilePass Selfie Login WordPress plugin allows unauthenticated users to log in as any registered account, including administrators, by bypassing identity verification. This could lead to unauthorized access and control over WordPress sites. The relevance and exposure of this plugin are key factor

CVE advisoryCRITICAL

CVE-2026-77001

Social Login & Sharing buttons WordPress Plugin Account Takeover Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A WordPress plugin for social login and sharing lacks proper security checks in its login handlers, allowing unauthenticated attackers to take over any user account, including administrator accounts. This vulnerability could lead to unauthorized access and control of WordPress sites.

CVE advisoryCRITICAL

CVE-2026-77000

WP Social Media Login Unauthenticated User Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A flaw in a WordPress social login plugin allows unauthenticated attackers to access any user account, including administrators, by supplying an email address without verifying the social login completion. This could lead to unauthorized site access and control.