NVD disclosure day

Published threat advisories for August 25, 2026

CVE advisoryCRITICAL

CVE-2026-80138

ClipBucket V5 Installer Remote Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ClipBucket V5's web installer allows unauthenticated attackers to execute arbitrary server commands by submitting a crafted request to the installer. This could compromise the web server's integrity, impacting the availability and confidentiality of data and services. It is important to determine if

CVE advisoryCRITICAL

CVE-2026-79911

TOTOLINK N600R CGI Handler Stack Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow vulnerability in the CGI handler of the TOTOLINK N600R allows for remote exploitation by manipulating a configuration argument. This could lead to unauthorized system access or complete device compromise. The exploit has been publicly disclosed, increasing the risk of its use.

CVE advisoryCRITICAL

CVE-2026-16645

Drupal PhotoSwipe Missing Authorization Leads to Forceful Browsing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Drupal PhotoSwipe module, allowing forceful browsing due to missing authorization. This could enable unauthorized access to image files on affected Drupal sites. It is important to confirm if this module and its impacted versions are in use within our environment.

CVE advisoryCRITICAL

CVE-2026-16644

Drupal Webform REST Forceful Browsing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability in the Drupal Webform REST module allows forceful browsing, potentially exposing sensitive data. This issue affects a commonly used web integration tool and could allow unauthorized access to webform submissions and related information. Organizations should verify if they use th

CVE advisoryCRITICAL

CVE-2026-16641

Drupal Commerce Elavon Vulnerability Allows Full System Compromise

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Drupal Commerce Elavon module, potentially allowing unauthenticated network access to impact system integrity, availability, and sensitive data. This issue is relevant to public-facing e-commerce applications that process financial transactions.

CVE advisoryCRITICAL

CVE-2026-16639

Drupal Internationalization Single Sign-On Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in the Drupal Internationalization Single Sign-On module, allowing unauthorized access. If reachable, an attacker could exploit an alternate path to bypass authentication, potentially compromising systems. This issue affects specific versions of the module, and its critical

CVE advisoryCRITICAL

CVE-2026-78655

Punk Plugin TOTP Session Replay Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in a Perl plugin for TOTP authentication that could allow an attacker to bypass the limit on second-factor authentication attempts by replaying an earlier session cookie. This is possible if session data is not managed server-side. This could impact systems using this plugin for authentication if

CVE advisoryCRITICAL

CVE-2026-78619

Punk Plugin TOTP Recovery Code Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a two-factor authentication plugin allows an attacker with a user's password and their own recovery code to bypass authentication. This occurs due to incorrect numerical comparison of user identifiers, enabling unauthorized account access when the recovery code is used. This issue impacts user accoun

CVE advisoryCRITICAL

CVE-2026-68525

Apache Tomcat FORM Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability in Apache Tomcat's FORM authentication could allow attackers to bypass security constraints and gain unauthorized access to resources. This could happen if a reachable Tomcat server processes a crafted request, potentially exposing sensitive information or functionality. This is

CVE advisoryCRITICAL

CVE-2026-65905

Apache Tomcat DIGEST Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in Apache Tomcat's DIGEST authenticator, potentially allowing attackers to replay authenticated requests under specific conditions. This could enable unauthorized access to systems relying on this authentication method. Readers should confirm if their Apache Tomcat deployme

CVE advisoryCRITICAL

CVE-2026-65637

Apache Tomcat Improper Input Validation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper input validation vulnerability in Apache Tomcat could allow attackers to affect service behavior if reachable. This issue impacts Apache Tomcat, a widely deployed web server and servlet container. The exact impact on data is currently uncertain.

CVE advisoryCRITICAL

CVE-2026-65182

Apache Tomcat Security Constraint Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Improper Access Control vulnerability in Apache Tomcat may allow an attacker to bypass security constraints when specific path configurations are not ordered correctly, potentially exposing application resources. This is a concern because Tomcat is widely deployed and often exposed to the internet, making it a relev

CVE advisoryCRITICAL

CVE-2026-62862

Typebot Email Login Brute Force Vulnerability Enables Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in self-hosted Typebot versions up to 3.17.1 allows attackers to gain account takeover by brute-forcing weak, time-limited email magic links. This could lead to unauthorized access to user bots and connected credentials if email-based authentication is configured. Deployments using only OAuth or SSO are

CVE advisoryCRITICAL

CVE-2026-80104

DB-GPT Arbitrary File Write Via Skill Upload Leading to Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in DB-GPT allows unauthenticated remote attackers to execute arbitrary code by uploading a crafted file. This flaw stems from the application's mishandling of uploaded filenames, enabling attackers to write files to unintended server locations. If the application imports these maliciously placed files,

CVE advisoryCRITICAL

CVE-2026-79290

Google Chrome Aura Use-After-Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Aura component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This requires user interaction, but the potential for code execution outside the browser's secure sandbox is a significant concern, potentially affecting user s

CVE advisoryCRITICAL

CVE-2026-79282

Chrome ANGLE Use After Free Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical use-after-free vulnerability exists in ANGLE within Google Chrome on Android, allowing remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact user devices if they interact with malicious web content. The immediate concern is to determine system relevance and

CVE advisoryCRITICAL

CVE-2026-79275

ANGLE Use After Free in Chrome Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in ANGLE, a component within Google Chrome, could permit a remote attacker to execute arbitrary code outside the browser's sandbox. This is achievable by directing a user to a specially crafted HTML page. Given its network-exploitability and potential for remote code execution, this vulne

CVE advisoryCRITICAL

CVE-2026-79257

Google Chrome Use After Free Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free flaw in Google Chrome's Views component may permit a remote attacker to execute arbitrary code outside the sandbox via a malicious HTML page. This could allow attackers to compromise user systems if they can escape the sandbox.

CVE advisoryCRITICAL

CVE-2026-79235

Google Chrome WebGL Use After Free Leads to Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's WebGL component could enable remote attackers to execute arbitrary code outside the sandbox by tricking users into visiting a malicious HTML page. This means an attacker could potentially compromise a user's system by leveraging this flaw.

CVE advisoryCRITICAL

CVE-2026-79232

Google Chrome Use After Free Vulnerability Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Aura component could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page, which requires user interaction. Understanding this flaw is important for assessing potential impact on your organization's digital environment.

CVE advisoryCRITICAL

CVE-2026-79200

Google Chrome Aura Use-After-Free Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Aura component permits remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This memory management flaw could compromise user security within the browser. Readers should assess the relevance and exposure of this issue to their organiza

CVE advisoryCRITICAL

CVE-2026-79189

ANGLE Out-of-Bounds Write in Chrome Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in ANGLE, a component of Google Chrome, due to an out-of-bounds write. This flaw may allow remote attackers to execute arbitrary code outside the browser's sandbox via a crafted HTML page. The issue is relevant to users accessing the internet, as a malicious webpage could trigger this ex

CVE advisoryCRITICAL

CVE-2026-79188

ANGLE Out-of-Bounds Write in Chrome Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in ANGLE, a Google Chrome component, may allow a remote attacker to execute arbitrary code by directing a user to a malicious HTML page. This could result in a loss of confidentiality, integrity, and availability for the affected user's system.

CVE advisoryCRITICAL

CVE-2026-79152

Google Chrome for Android CustomTabs Authorization Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An authorization flaw in Google Chrome's CustomTabs on Android allows a local attacker with a co-installed app to bypass web origin policies. This could potentially enable unauthorized interaction with web content. The relevance depends on the presence of such co-installed applications.

CVE advisoryCRITICAL

CVE-2026-79150

Chrome Use After Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact system confidentiality and integrity, and requires user interaction to exploit.

CVE advisoryCRITICAL

CVE-2026-79140

Google Chrome Use-After-Free in Views Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Views component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could lead to potential compromise of user systems when visited through normal web browsing. The relevance and exposure of affected systems need to be con

CVE advisoryCRITICAL

CVE-2026-79138

ANGLE Out of Bounds Write in Chrome Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Google Chrome's ANGLE component on Windows, allowing remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This requires a user to visit a malicious website, making it a concern for user security and data. The primary goal is to understand potential u

CVE advisoryCRITICAL

CVE-2026-79130

Google Chrome ANGLE Buffer Overflow Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability in ANGLE, used by Google Chrome, could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This poses a risk to user data and system integrity, and is classified as critical due to its network attack vector and potential for high impact.

CVE advisoryCRITICAL

CVE-2026-79129

Chrome for Android Use After Free in Sessions Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome on Android could allow remote attackers to execute arbitrary code outside the sandbox via UI interaction and social engineering. This affects widespread user software and could lead to unauthorized code execution on devices.

CVE advisoryCRITICAL

CVE-2026-79111

Chrome Dawn Code Execution via Crafted HTML

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's Dawn component could allow remote attackers to execute arbitrary code outside the sandbox via a malicious HTML page. This is a concern because web browsers frequently encounter untrusted content, creating a common attack surface for internet-based threats.

CVE advisoryCRITICAL

CVE-2026-79091

Chrome Bluetooth Use After Free Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome's Bluetooth component may permit remote attackers to execute arbitrary code through a malicious HTML page, potentially impacting system security. This vulnerability's impact relies on user interaction via social engineering.

CVE advisoryCRITICAL

CVE-2026-79078

FedCM Use-After-Free in Chrome Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's FedCM component allows remote attackers to execute arbitrary code outside the sandbox by tricking users into visiting a malicious HTML page. This critical flaw requires user interaction via social engineering, presenting a potential risk if exploited.

CVE advisoryCRITICAL

CVE-2026-79064

Google Chrome Use After Free in Network Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's network component could allow a remote attacker to execute code outside the sandbox via a malicious extension. This requires social engineering to trick a user into installing and interacting with the extension. The concern is whether users' Chrome browsers are exposed.

CVE advisoryCRITICAL

CVE-2026-79058

Google Chrome Password Spoofing Vulnerability CVE-2026-79058

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Google Chrome's password feature could allow an attacker with a compromised renderer process to spoof UI elements via a crafted HTML page, potentially deceiving users. This vulnerability, assessed as low severity by Chromium, is relevant due to Chrome's widespread use.

CVE advisoryCRITICAL

CVE-2026-79056

Use After Free in Chrome ServiceWorker Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free flaw in a widely used web browser's ServiceWorker component could allow remote attackers to execute arbitrary code outside the sandbox via a crafted webpage. While the component's security severity is low, its network-based attack vector and common exposure to untrusted web traffic warrant attention. C

CVE advisoryCRITICAL

CVE-2026-79052

Google Chrome Aura Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Aura component allows remote code execution outside the sandbox via a crafted HTML page. This could affect user systems if they visit such a page. The potential impact on business operations requires further analysis.

CVE advisoryCRITICAL

CVE-2026-79047

Chrome Use After Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome could allow a remote attacker to execute arbitrary code outside the sandbox if a user is tricked into visiting a malicious HTML page. This could affect user systems by enabling code execution.

CVE advisoryCRITICAL

CVE-2026-79043

ANGLE Out-of-Bounds Write in Chrome Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote attacker can exploit an out-of-bounds write vulnerability in ANGLE, a Google Chrome component, by directing users to a crafted HTML page. This could potentially allow arbitrary code execution outside the browser sandbox. The reachability is high as web browsers are frequently used to access untrusted content f

CVE advisoryCRITICAL

CVE-2026-79026

Google Chrome Use After Free in Extensions Allows Sandbox Escape

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome extensions could permit a remote attacker to execute arbitrary code outside the sandbox by leveraging social engineering to trick a user into installing a malicious extension. This could potentially impact system and user data.

CVE advisoryCRITICAL

CVE-2026-79019

ANGLE Out of Bounds Write Vulnerability in Chrome on Windows

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in ANGLE within Google Chrome on Windows, allowing remote attackers to potentially execute arbitrary code by tricking users into visiting a malicious HTML page. This could compromise system memory and bypass security sandboxes, warranting an investigation into its presence and exposure w

CVE advisoryCRITICAL

CVE-2026-79012

Chrome Safebrowsing Use After Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome's Safebrowsing feature may permit remote attackers, through social engineering, to execute arbitrary code outside the sandbox by visiting a crafted HTML page. The specific impact on your environment is currently uncertain.

CVE advisoryCRITICAL

CVE-2026-78989

ANGLE Out of Bounds Read Vulnerability in Google Chrome for Windows

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the ANGLE graphics component of Google Chrome on Windows, potentially allowing remote attackers to execute arbitrary code by luring users to a malicious HTML page. This could impact system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-78985

Google Chrome FileSystem Incorrect Reference Resolution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's FileSystem component could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, if users are tricked into visiting it. This could affect the confidentiality, integrity, and availability of systems.

CVE advisoryCRITICAL

CVE-2026-78964

Sync Use After Free in Google Chrome on iOS

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability in Google Chrome on iOS could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. While user interaction is required, the flaw has a critical CVSS score, necessitating confirmation of relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-78951

Chrome Service Worker Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's ServiceWorker component allows a remote attacker to execute arbitrary code outside the sandbox by directing a user to a malicious HTML page. This could lead to unauthorized actions on the user's system.

CVE advisoryCRITICAL

CVE-2026-78948

Chrome WebGL Buffer Overflow Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow vulnerability in Google Chrome's WebGL component could allow a remote attacker to execute arbitrary code outside the sandbox by directing a user to a specially crafted HTML page. This could potentially impact user systems or sensitive data.

CVE advisoryCRITICAL

CVE-2026-78945

Chrome Use After Free Vulnerability in Views Component Allows Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Views component allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact the confidentiality, integrity, and availability of user systems and data.

CVE advisoryCRITICAL

CVE-2026-78939

Chromecast Use After Free in Chrome Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Chromecast component enables a remote attacker, who has already compromised the renderer process, to execute arbitrary code outside the sandbox via a malicious HTML page, potentially impacting system stability.

CVE advisoryCRITICAL

CVE-2026-78937

Chrome for Android Use After Free Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on Android could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, requiring social engineering for exploitation. This could potentially impact user data and system integrity if the vulnerability is reachable and relevant withi

CVE advisoryCRITICAL

CVE-2026-78935

Chrome on iOS Uninitialized Variable Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in Google Chrome on iOS allows remote attackers to execute code outside the sandbox via a crafted HTML page. While exploitation requires user interaction with a malicious website, making it unlikely, the critical severity warrants attention.

CVE advisoryCRITICAL

CVE-2026-78909

Chrome Use After Free in Views Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Views component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page, requiring social engineering. This affects a widely used product processing external content, potentially impacting system data and user data.

CVE advisoryCRITICAL

CVE-2026-78900

Chrome Media Vulnerability Allows Remote Code Execution Outside Sandbox

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's media handling could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This is a concern for widely used browsers that are constantly exposed to external web-based threats.

CVE advisoryCRITICAL

CVE-2026-65093

NVIDIA OpenShell Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

NVIDIA OpenShell for Linux contains a vulnerability allowing an attacker with limited access to escape its sandbox. This could enable unauthorized code execution, privilege escalation, data tampering, and information disclosure, posing a significant security risk if the technology is present and reachable in your envir

CVE advisoryCRITICAL

CVE-2026-65083

NVIDIA OpenShell Sandbox API Vulnerability Allows Code Execution and Privilege Escalation.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in NVIDIA OpenShell for Linux's sandbox provisioning API could allow an attacker to execute code, escalate privileges, or disclose information. This occurs if an attacker can exploit an incomplete list of disallowed inputs.

CVE advisoryCRITICAL

CVE-2026-45018

Chainlit MCP Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Chainlit, a framework for building conversational AI applications, has a vulnerability allowing unauthenticated attackers to execute arbitrary shell commands with the privileges of the Chainlit process. This occurs when specific features are enabled, exposing an endpoint that accepts user-controlled commands without pr

CVE advisoryCRITICAL

CVE-2026-79787

Alluxio S3 Proxy Authentication Bypass via Unverified Signatures

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Alluxio's S3 REST proxy in its default configuration fails to verify AWS Signature Version 4, allowing unauthenticated attackers to impersonate any user and access, modify, or delete arbitrary data. This vulnerability is reachable via the network and requires attention to confirm usage and exposure.

CVE advisoryCRITICAL

CVE-2026-78379

Strands Agents Tools Prompt Injection Allows Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the `python_repl` tool for Amazon Strands Agents Tools may allow remote actors to execute arbitrary Python code by bypassing consent gates through crafted prompts. This could potentially impact the agent's host system. Readers should verify if their deployed agent applications utilize this tool and c

CVE advisoryCRITICAL

CVE-2026-76197

Adobe Campaign Classic OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is affected by an OS command injection vulnerability. This flaw could allow an unauthenticated attacker to execute arbitrary code on the system, potentially leading to a compromise. This issue is relevant if Adobe Campaign Classic is accessible via the network.

CVE advisoryCRITICAL

CVE-2026-76193

Adobe Campaign Classic SSRF Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic has a Server-Side Request Forgery vulnerability that could allow an attacker to execute arbitrary code. This vulnerability is reachable via the network and does not require user interaction, potentially impacting system data and service behavior.

CVE advisoryCRITICAL

CVE-2026-79782

rclone Security Token Leak via HTTPS to HTTP Redirect

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in rclone allows for the exposure of sensitive security tokens if traffic is redirected from HTTPS to HTTP. This could enable attackers to intercept plaintext HTTP traffic and capture AWS STS session tokens, potentially leading to unauthorized access to cloud storage.

CVE advisoryCRITICAL

CVE-2026-79675

NLTK JVM Option Injection Arbitrary Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The NLTK library may allow for arbitrary code execution due to a flaw in how it handles Java Virtual Machine options passed to its `java()` function. If an attacker can reach this function with crafted input, they could inject malicious JVM flags, potentially leading to system compromise. It is important to understand

CVE advisoryCRITICAL

CVE-2026-55640

Nextcloud MCP Server Unauthenticated Webhook Deletes Vector Embeddings

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Nextcloud MCP Server has a vulnerability where an unauthenticated network attacker can delete or re-index vector embeddings and destroy the semantic search index. This impacts the integrity and availability of AI assistant integrations by allowing unauthorized manipulation of AI search data. This issue is fixed in vers

CVE advisoryCRITICAL

CVE-2026-55546

QWED-MCP Math Expression Verification Command Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in QWED-MCP's math expression verification allows arbitrary OS command execution, data compromise, and secret exfiltration if untrusted input is passed to a library function via custom integrations. The default configuration does not expose this risk.

CVE advisoryCRITICAL

CVE-2026-55536

PraisonAI Browser Server Unauthorized Automation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in PraisonAI's browser server could permit unauthorized browser automation. The issue stems from how Chrome extension origins are validated, potentially allowing malicious commands. This could result in unintended browser actions if the system is reachable.

CVE advisoryCRITICAL

CVE-2024-58378

Nokogiri Use-After-Free in XML Reader Component.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability exists in Nokogiri's XML Reader component when specific configurations, including DTD validation and XInclude expansion, are enabled. Processing a crafted XML document under these conditions could lead to system instability or unauthorized access. This issue impacts Ruby applications usin

CVE advisoryCRITICAL

CVE-2022-51000

Nokogiri Vulnerabilities Through Bundled Libraries

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Nokogiri library, when processing untrusted XML or XSL stylesheets, may be vulnerable to denial-of-service, memory disclosure, or code execution. This is due to underlying issues in bundled versions of libxml2 and libxslt. The risk depends on how applications integrate and use the library to process external data.

CVE advisoryCRITICAL

CVE-2026-16286

TRtek Software Repository Management Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in TRtek's Software Repository Management that allows an attacker to upload a web shell to a web server, potentially leading to server compromise. This issue is accessible via the network, and its impact is uncertain without knowing system usage and exposure within an organization.

CVE advisoryCRITICAL

CVE-2026-77998

Joomla SAML SSO Authentication Bypass via Signature Validation Flaw

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Joomla extensions allows unauthenticated attackers to bypass authentication and log in as any user, including administrators. This is achieved by submitting a crafted SAMLResponse that triggers an error during signature verification, bypassing security checks. This issue affects authenticati

CVE advisoryCRITICAL

CVE-2026-79664

Ech0 Access Token Revocation Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Ech0 where access tokens created with a "never-expire" option may not be properly revoked, allowing an attacker to maintain perpetual authenticated access if a token is stolen. This could lead to unauthorized persistent access until the system's JSON Web Token secret is rotated.

CVE advisoryCRITICAL

CVE-2026-79657

NLTK Remote Code Execution via Unsafe Pickle Load.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A remote code execution vulnerability exists in NLTK's pickle loaders, allowing attackers to execute arbitrary commands by crafting malicious model or tokenizer artifacts. This occurs when the library trusts entire module namespaces instead of specific safe callables, enabling dangerous functions to be invoked during a

CVE advisoryCRITICAL

CVE-2026-57910

WatchGuard Agent Improper Authentication Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authentication vulnerability exists in the WatchGuard Agent, potentially allowing an unauthenticated attacker with network access to execute arbitrary code with elevated privileges. This could impact system integrity and availability if the agent is reachable. Confirming the use and network exposure of this

CVE advisoryCRITICAL

CVE-2026-55976

Apache Hive SSRF via Avro Schema Resolution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Hive allows authenticated users with table creation privileges to cause the Hive server to fetch attacker-controlled URLs when resolving Avro table schemas, potentially exposing cloud instance metadata or internal network services. This is relevant if your environment uses Avro tables and sens

CVE advisoryCRITICAL

CVE-2026-49845

Apache Hive Metastore SQL Injection Affects Partition Metadata

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A SQL injection vulnerability in Apache Hive Metastore allows authenticated users to manipulate partition metadata through crafted partition names. This could lead to unintended modifications or incorrect targeting of data, statistics, and cache operations within tables when direct SQL is enabled. The primary concern i

CVE advisoryCRITICAL

CVE-2026-78568

Total Donations Plugin SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Total Donations WordPress plugin, allowing unauthenticated attackers to extract sensitive database information. This flaw arises from insufficient handling of user-supplied parameters within SQL queries. Confirm if this plugin is used and accessible online, as it cou

CVE advisoryCRITICAL

CVE-2026-77138

TYPO3 Extension PHP Object Injection Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A TYPO3 extension vulnerability allows remote, unauthenticated attackers to execute code on a server by sending a specially crafted cookie, leading to PHP Object Injection. This issue is relevant because TYPO3 extensions are often used in public-facing websites, and the vulnerability is reachable via the network withou

CVE advisoryCRITICAL

CVE-2026-77136

Powermail Fluid Template Injection Leads to Server Information Disclosure and Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in a web form's sender name field allows unauthenticated users to inject and execute arbitrary code. This could lead to the disclosure of server information and application source code, or even remote code execution, if the field is configured in a specific way. The issue is reachable via a normal form

CVE advisoryCRITICAL

CVE-2026-63586

Web Management Authentication Bypass Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in a web-based management interface allows unauthenticated attackers to execute arbitrary commands as root. This occurs because usernames from the Authorization header are directly inserted into system commands without sanitization. If the interface is network-accessible, an attacker could gain full con

CVE advisoryCRITICAL

CVE-2026-78477

Jawn Theme for WordPress Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical privilege escalation vulnerability exists in the Jawn WordPress theme, allowing unauthenticated attackers to gain administrator access. This could lead to unauthorized control and modification of websites. Organizations using this theme should identify affected instances and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-13214

OCPP Client Stack Buffer Overflow in Zephyr

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack buffer overflow in the OCPP client's handling of GetConfiguration requests can be triggered remotely. An attacker controlling the central system or intercepting communications can cause a denial of service or potentially remote code execution on charge point devices.

CVE advisoryCRITICAL

CVE-2026-78683

NLTK TransitionParser Unsafe Pickle Deserialization Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

NLTK's TransitionParser contains a vulnerability that allows arbitrary Python code execution when an application loads a specially crafted model file due to unsafe deserialization. This could impact systems processing natural language models.

CVE advisoryCRITICAL

CVE-2026-78676

GitPython Configuration Injection Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in GitPython allows attackers to execute arbitrary code by crafting configuration files that, when written by GitPython, inject malicious directives. This could occur through unrelated GitPython write operations, potentially leading to code execution via Git hooks. Readers should confirm GitPython usage

CVE advisoryCRITICAL

CVE-2026-72702

Grav CMS Origin Validation Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Grav CMS has an origin validation bypass vulnerability due to incomplete validation of the Referer header. This could allow an attacker to trick the system into treating a malicious domain as a trusted one, potentially leading to unauthorized access. The issue is reachable by simply sending a specially crafted Referer

CVE advisoryCRITICAL

CVE-2026-56710

Grav Login Plugin Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Grav Login plugin that allows an attacker with user write permissions to bypass brute-force protections on high-privilege accounts. This could remove security measures from critical administrative accounts, potentially weakening their security.

CVE advisoryCRITICAL

CVE-2026-56705

Adminer ODBC Parameter Injection Leading to Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Adminer fails to sanitize server input, allowing unauthenticated attackers to inject ODBC parameters and execute remote code by writing PHP to the web root. This vulnerability, if reachable, could compromise affected systems through the execution of malicious trace files.