NVD disclosure day

Published threat advisories for August 24, 2026

CVE advisoryCRITICAL

CVE-2026-78267

TranslatePress Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in TranslatePress, a website translation plugin. If reachable, attackers could gain elevated system access, potentially leading to unauthorized control over website content and functionality. Organizations using this plugin should assess their exposure and pl

CVE advisoryCRITICAL

CVE-2026-78265

The Events Calendar Unauthenticated PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a widely used WordPress event management plugin allows unauthenticated attackers to inject PHP objects, potentially leading to arbitrary code execution on the server. This could compromise website data and allow for a full site takeover. The issue is externally exposed and relevant to any pu

CVE advisoryCRITICAL

CVE-2026-78262

WP Project Manager Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the WP Project Manager plugin, potentially allowing attackers to execute arbitrary code on affected servers. This could lead to a full system compromise if the plugin is reachable. It is important to confirm if this plugin is in use and assess its exposure

CVE advisoryCRITICAL

CVE-2026-77337

CakePHP Authentication Bypass Due to Forgeable Tokens

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in CakePHP's authentication plugin allows an attacker to bypass authentication and potentially exhaust system resources by exploiting unencrypted, forgeable legacy tokens. This could lead to unauthorized access to applications and service disruptions.

CVE advisoryCRITICAL

CVE-2026-32563

WordPress ACPT Pro Plugin PHP Object Injection.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability exists in a WordPress plugin, allowing unauthenticated attackers to execute arbitrary code. This can lead to a compromise of website data and availability if the plugin is reachable. Confirm plugin presence and assess exposure to understand potential impact.

CVE advisoryCRITICAL

CVE-2026-32559

UltimateAI Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the UltimateAI plugin, allowing authenticated users to upload arbitrary files. This could enable malicious code execution or unauthorized access to sensitive data on affected systems. The primary concern is to confirm the plugin's presence and exposure within the environment.

CVE advisoryCRITICAL

CVE-2026-32555

Boost Plugin Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Boost, a web technology, that could allow attackers to access or manipulate sensitive data. This flaw is reachable via network requests and may impact system and user data. It is important to confirm if this technology is deployed and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-32554

WooBeWoo Product Filter Pro SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in a WordPress product filter plugin, allowing unauthenticated attackers to inject malicious SQL code. If reachable, this could lead to unauthorized access or modification of sensitive data, potentially impacting business operations and customer trust. Confirmation is neede

CVE advisoryCRITICAL

CVE-2026-77635

CakePHP FunctionsBuilder SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in CakePHP's `FunctionsBuilder::jsonValue()` function when used with PostgresDriver, allowing attackers to manipulate database queries through user-supplied data in the `jsonPath` parameter. This could lead to unauthorized access or modification of sensitive data.

CVE advisoryCRITICAL

CVE-2026-78555

RansomLook API Keys Exposed in Admin Page Source Code

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

RansomLook inadvertently exposed complete API keys in the HTML source of its authenticated admin API keys page. An attacker could recover these credentials by inspecting the page source, allowing them to authenticate with the privileges of the compromised key and access private data. This matters if sensitive data is a

CVE advisoryCRITICAL

CVE-2026-39975

Combodo iTop Unauthenticated Code Execution via .readonly File Deletion.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Combodo iTop allows unauthenticated users to execute code by deleting a file that prevents write actions. If reachable, this could impact the integrity and availability of IT service management operations. Uncertainty exists regarding specific affected versions and business impact.

CVE advisoryCRITICAL

CVE-2026-76835

OAuth2 Proxy Authentication Bypass Via X-Forwarded-Uri

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in OAuth2 Proxy allows unauthenticated attackers to bypass authentication by sending a crafted `X-Forwarded-Uri` header. This header manipulation causes the proxy to skip authentication for protected resources when it incorrectly trusts the client's supplied URI. The issue arises when the proxy's defaul

CVE advisoryCRITICAL

CVE-2026-71921

DrayTek VigorSwitch Pre-Authentication Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical pre-authentication command injection vulnerability exists in multiple DrayTek VigorSwitch models within the setget.cgi interface, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by sending crafted input due to insufficient filtering. This could lead to complete co

CVE advisoryCRITICAL

CVE-2026-71914

DrayTek VigorAP Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection flaw exists in DrayTek VigorAP models due to insufficient UDP message validation in the `dray_apm` component, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This could impact device integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-78329

Apache Camel Undertow Header Filtering Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper input validation vulnerability in the Apache Camel Undertow component could allow manipulation of HTTP headers. If reachable, this may lead to unintended message routing or processing of unsupported headers, impacting message integrity. Confirmation of the affected technology's presence and exposure in your

CVE advisoryCRITICAL

CVE-2026-77915

rConfig Authentication Bypass Allows Administrator Account Self-Registration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in rConfig allows unauthenticated attackers to register as administrators. This flaw in the web interface's registration functionality could grant attackers full control, exposing sensitive device credentials and user data.

CVE advisoryCRITICAL

CVE-2026-66906

Apache Camel Azure Blob Relative Path Traversal Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A relative path traversal vulnerability exists in the Apache Camel Azure Storage Blob component, allowing an attacker to write files to arbitrary locations on the server. This occurs when downloading blobs, as the component may not properly sanitize blob names, potentially leading to overwrites outside the intended dir

CVE advisoryHIGH

CVE-2026-19685

NetworkManager Local Privilege Escalation via CA Path Manipulation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

NetworkManager's handling of WPA-Enterprise CA paths is flawed, allowing an unprivileged local user to bypass server certificate validation. This could enable credential theft via a rogue access point by pointing connection profiles at attacker-controlled directories. Confirm relevance and exposure in your environment.

CVE advisoryCRITICAL

CVE-2025-36939

OpenThread MLE Packet Handling Vulnerabilities Lead to Denial of Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

OpenThread's handling of network packets contains vulnerabilities that could permit an authenticated attacker on the same network to cause a denial of service. These issues include assertion failures and a stack-based buffer overflow. Readers should care to confirm if this technology is in use and exposed, as exploitat

CVE advisoryCRITICAL

CVE-2026-76071

Netis NC63 Stack Buffer Overflow Leads to Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Netis NC63 firmware allows unauthenticated remote attackers to execute code as root. Exploiting a stack buffer overflow via a crafted web request can lead to a complete device compromise. This affects internet-facing devices and requires immediate attention to confirm exposure and plan remed

CVE advisoryCRITICAL

CVE-2026-76070

Netis NC63 Stack Buffer Overflow via Login Password Parameter

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical buffer overflow vulnerability exists in Netis router firmware, allowing unauthenticated remote attackers to potentially execute arbitrary code with root privileges by submitting an oversized Base64-encoded password. This could lead to a complete compromise of the affected device.

CVE advisoryCRITICAL

CVE-2026-78387

RansomLook Admin Config Editor Authorization Weakness

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

RansomLook's web configuration editor has an authorization weakness, allowing authenticated low-privileged users to alter critical settings like security, notifications, and authentication. This could disrupt services, redirect data, or expose sensitive credentials such as passwords and API keys. The vulnerability is r

CVE advisoryCRITICAL

CVE-2026-19874

Metal Gear Online 3 Lobby Data Heap Overflow Leads to Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow vulnerability in Metal Gear Online 3 allows an attacker to overwrite game process memory by sending malformed lobby data, potentially leading to arbitrary code execution. While the vulnerability is exploitable over the network, the chance of exposure is considered very unlikely as it affect

CVE advisoryCRITICAL

CVE-2026-78372

RansomLook Unauthorized Access to Private Group and Ransom Note Data.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

RansomLook has a flaw where authorization checks are not consistently enforced for private groups, markets, and ransom notes. This allows unauthenticated attackers to remotely access sensitive information, including private group names, ransom note content, and metadata, through web views and API endpoints. This could

CVE advisoryCRITICAL

CVE-2026-78370

RansomLook Unauthenticated Database Export Information Disclosure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in RansomLook's legacy database export functionality allows unauthenticated remote users to retrieve private information. This could expose sensitive data such as ransomware intelligence or victim details, making it crucial to confirm if this system is in use and assess potential data privacy exposure.

CVE advisoryCRITICAL

CVE-2026-67602

phpIPAM Authentication Bypass via REST API Object Cache

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the REST API of an IP address management application that allows unauthenticated attackers to bypass authentication. This bypass enables attackers to use a numerical database identifier as an API token, granting them full access to read, write, and delete all IP address management records.

CVE advisoryCRITICAL

CVE-2026-59568

Zscaler Client Connector Remote Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Critical vulnerabilities in Zscaler Client Connector permit an unauthenticated user to execute arbitrary code, potentially impacting the local system. While typically installed on end-user devices, its reachability and presence in the environment need confirmation to assess relevance. No specific versions or exploits a

CVE advisoryCRITICAL

CVE-2026-59564

Zscaler Client Connector Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in Zscaler Client Connector communications, potentially allowing unauthorized access to Zscaler services. Readers should care because this could impact the management and identity functions of the Zscaler service if the technology is in use.

CVE advisoryCRITICAL

CVE-2026-78365

Roskus Prospero Flow CRM Supplier API Authorization Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization bypass vulnerability exists in the supplier API of Roskus Prospero Flow CRM, allowing any authenticated user to read, modify, or reassign another company's supplier records by sending a PUT request with a modified company ID. This could lead to unauthorized data manipulation.

CVE advisoryCRITICAL

CVE-2026-32558

Affiliate Pro WooCommerce WordPress Plugin Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the Affiliate Pro plugin for WooCommerce and WordPress, potentially allowing attackers to gain unauthorized control. Reachable via network requests, this issue could lead to elevated privileges and unauthorized data access. Confirming relevance and exposur

CVE advisoryCRITICAL

CVE-2026-32551

Woo Essential Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a WordPress plugin. If reachable, an attacker could inject malicious SQL commands to potentially access sensitive database information. This is relevant because the plugin is often used in public-facing websites.

CVE advisoryCRITICAL

CVE-2026-28165

Digits Unauthenticated Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical privilege escalation vulnerability exists in the Digits technology, which can be exploited by unauthenticated actors over the network. If affected systems are in use, this could allow unauthorized control. Organizations should verify if Digits is deployed and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-66897

LXD Path Traversal Leading to Host Root Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions or by launching a crafted image to overwrite arbitrary host files as root, potentially leading to code execution. This occurs due to a discrepancy between LXD's path validation and file creation proce

CVE advisoryCRITICAL

CVE-2026-78211

4MOSAn GCB Doctor OS Command Injection via ADOdb Test Page

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in 4MOSAn GCB Doctor software, allowing unauthenticated remote attackers to execute arbitrary commands via an ADOdb test page parameter. This could lead to unauthorized system access and compromise. The technical readers and security-aware leaders should care because this issue allows remote atta

CVE advisoryCRITICAL

CVE-2026-78167

EFM ipTIME T16000M Improper Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in EFM ipTIME routers' session validation handler allows remote attackers to bypass authentication. This could grant unauthorized access and control over the devices, which often serve as network gateways. The vendor has not responded to disclosure.

CVE advisoryCRITICAL

CVE-2026-78207

exceljs-hardened Prototype Pollution via DeepMerge

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A prototype pollution vulnerability exists in a software library used for processing Excel files, specifically in its `deepMerge` function. If reachable, an attacker could modify cell notes in a crafted Excel file to alter Object.prototype, affecting all plain objects. This could lead to unpredictable consequences with