NVD disclosure day

Published threat advisories for August 26, 2026

CVE advisoryCRITICAL

CVE-2026-75340

Jetlinks Community SSRF Vulnerability in Device Metadata Import

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical server-side request forgery vulnerability exists in the JetLinks community platform's device metadata import interface, potentially allowing attackers to make the server perform arbitrary requests. This could lead to the disclosure of sensitive information or manipulation of internal services. The primary co

CVE advisoryCRITICAL

CVE-2026-75338

Disconf Configuration APIs Exposed Without Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a distributed configuration management platform allows unauthenticated access to sensitive configuration data. Attackers can retrieve all configuration items and files due to exposed, unprotected APIs. This could compromise system settings and operational data.

CVE advisoryCRITICAL

CVE-2026-75336

Funiture SQL Injection in Backend Tool Interfaces

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical SQL injection vulnerability exists in Funiture's backend tool interfaces, allowing network-reachable attackers to potentially access, modify, or delete sensitive data. Confirming if this Funiture component is deployed and exposed in your environment is crucial for risk assessment.

CVE advisoryCRITICAL

CVE-2026-75332

Zyplayer-Doc SSRF Vulnerability via WikiPageWebService Download

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Zyplayer-Doc is susceptible to a critical Server-Side Request Forgery vulnerability through its WikiPageWebService.download() function, potentially allowing attackers to compel the server to make requests to arbitrary internal or external resources. This could lead to unauthorized access and disclosure of sensitive inf

CVE advisoryCRITICAL

CVE-2026-75330

super-diamond-server SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the front-end interface of a server application, allowing unauthenticated attackers to manipulate database queries. If reachable, this could expose or alter sensitive system data. Organizations should confirm if they use this application and are exposed to this input to mitigate

CVE advisoryCRITICAL

CVE-2026-65956

KubePi Unauthorized Access to SSO Configuration and Account Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in KubePi allows unauthorized users to access and modify Single Sign-On (SSO) configurations, potentially leading to account takeover or privilege escalation. This issue also permits the abuse of a connectivity-test function for server-side request forgery.

CVE advisoryCRITICAL

CVE-2026-75329

Super Diamond Server Configuration Service Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated flaw in super-diamond-server's configuration service allows attackers to retrieve sensitive project details, including credentials, via a TCP request. If this service is reachable, unauthorized access to this information could impact data security.

CVE advisoryCRITICAL

CVE-2026-65641

Unauthenticated SMB Authentication Coercion Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists where an unauthenticated attacker can force a service account to authenticate over the network via SMB. This could potentially expose system or user data to unauthorized access. It is important to determine if this technology is used and exposed in your environment.

CVE advisoryCRITICAL

CVE-2025-51679

openRISC OR1200 RTL Netlist Mismatch

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the openRISC OR1200 due to a mismatch between its RTL design and netlist, potentially causing unexpected behavior. This hardware design issue could impact system integrity if the component is in use. Confirming the presence and relevance of openRISC OR1200 implementations is necessary

CVE advisoryKnown Exploit

CVE-2026-60004

Gitea Diffpatch API Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Gitea, a self-hosted development platform, allowing remote code execution via the diffpatch API. An attacker could exploit this by sending a malicious patch to install a Git hook, enabling them to run shell commands. This could compromise the Gitea service account and associated syste

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-26448

Stomper Use-After-Free Leads to Heap Corruption and Crash.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in a message broker allows for a heap corruption and process crash. If a client sends specific sequences of network frames, the broker may attempt to use freed memory. This could impact the availability and integrity of message processing services.

CVE advisoryCRITICAL

CVE-2025-70290

Denx U-Boot ZFS Integer Overflow Leads to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in Denx U-Boot's ZFS filesystem support may allow a malicious actor to cause incorrect memory allocation and out-of-bounds access, potentially leading to a crash or arbitrary code execution during the boot process. The primary concern is determining if the affected bootloader is in use and reachable

CVE advisoryCRITICAL

CVE-2026-75325

DWSurvey Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

DWSurvey applications have an authentication bypass vulnerability allowing unauthenticated attackers network access to sensitive data and functions via specific API parameters. The potential for unauthorized access to system data and service behavior warrants confirmation of its use and assessment of any exposure.

CVE advisoryCRITICAL

CVE-2026-51106

TokTok qTox Denial of Service via Serialization Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A denial of service vulnerability exists in TokTok qTox, impacting its data serialization component. This flaw could disrupt the application's normal operation if triggered under specific conditions. The exact impact beyond service disruption is uncertain, and the vulnerability appears to require local access.

CVE advisoryCRITICAL

CVE-2026-19485

Vertex AI Search Predictable Resource Name Vulnerability Allows Data Access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Cloud Vertex AI Search for Commerce, prior to an April 2026 patch, could allow an attacker with knowledge of a victim's project number to access staged data and error logs through predictable bucket names. This could lead to unauthorized read and write access to sensitive information. The issu

CVE advisoryCRITICAL

CVE-2025-61165

Cohere North AI Arbitrary File Upload Leading to Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in a cohere North AI component, potentially allowing attackers to execute arbitrary code by uploading a crafted file. Because this API endpoint is often externally exposed, it could impact system confidentiality, integrity, and availability. It is important to confi

CVE advisoryCRITICAL

CVE-2026-81032

NebulaGraph Unauthenticated Runtime Configuration Access and Modification.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

NebulaGraph exposes its runtime configuration through an unauthenticated HTTP service, allowing unauthorized access to sensitive settings and modification of critical parameters. This could enable attackers to alter daemon behavior, disable security features, or change access controls, potentially leading to system com

CVE advisoryCRITICAL

CVE-2026-80428

Unauthenticated PHP Object Injection via ILIAS Shibboleth Logout Endpoint.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The ILIAS application has a vulnerability where it deserializes unauthenticated session data through its Shibboleth logout endpoint. This can allow an unauthenticated attacker to achieve code execution as the web server user by placing malicious serialized objects into session data. The vulnerability is reachable witho

CVE advisoryCRITICAL

CVE-2026-54569

SENAITE.CORE JSON API Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SENAITE.CORE's JSON API allows unauthenticated remote code execution by chaining two requests. This could lead to the exposure or modification of sensitive laboratory data, files, and accounts, and disruption of service. Confirming the presence and reachability of the affected system is crucial to un

CVE advisoryCRITICAL

CVE-2026-80589

Linux Kernel Block Layer Timer Bug

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's block layer can cause system instability or crashes due to improper handling of disk initialization timers. This issue arises when a disk probe fails before the disk is fully added, and a timer remains active on a freed request queue, potentially leading to a use-after-free conditi

CVE advisoryCRITICAL

CVE-2026-80587

Linux Kernel MPTCP Suboption Combination Flaw.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's MPTCP implementation allows for incorrect handling of certain mutually exclusive suboptions, potentially leading to system compromise if MPTCP is in use and reachable. The specific impact depends on MPTCP's active deployment within an environment.

CVE advisoryCRITICAL

CVE-2026-80561

Linux Kernel libceph Unsafe Decode Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's Ceph component allows a malicious storage device to cause out-of-bounds reads by sending malformed data, potentially leading to memory corruption. This can be triggered during requests for storage lock information and may affect system stability.

CVE advisoryCRITICAL

CVE-2026-80557

Linux Kernel libceph Out-of-Bounds Read leads to watcher count corruption.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Linux kernel's Ceph client has an out-of-bounds read vulnerability in the `decode_watchers` function due to missing bounds checks. A malicious or compromised storage device could exploit this by sending a malformed response, potentially corrupting watcher count data and leading to system instability or crashes.

CVE advisoryCRITICAL

CVE-2026-80528

Linux Kernel Ceph Reclaim Crash Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Linux kernel vulnerability exists where specific filesystem operations can lead to a kernel crash. This occurs due to improper handling of Ceph data during memory reclamation, potentially impacting system stability. Confirming environmental relevance is key.

CVE advisoryCRITICAL

CVE-2026-75062

Google Langfun Eval Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in a Python library allows remote attackers to execute arbitrary Python code by sending specially crafted inputs that cause un-sandboxed code evaluation. This issue impacts applications using the default `lf.query` protocol and could lead to unauthorized code execution within the host applicati

CVE advisoryCRITICAL

CVE-2026-74752

Linux Kernel SCTP Cookie Authentication Validation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's SCTP implementation allows unauthenticated network access to cause out-of-bounds reads or writes when cookie authentication is disabled, potentially enabling local privilege escalation. This issue could impact kernel memory and integrity, requiring careful triage to identify affect

CVE advisoryCRITICAL

CVE-2026-74751

Linux Kernel RISC-V ZBB Strnlen Out-of-Bounds Read

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's RISC-V ZBB-optimized `strnlen` function could allow an issue if triggered. This could lead to system instability or crashes by reading past a boundary. This affects systems using the Linux kernel on RISC-V architectures.

CVE advisoryCRITICAL

CVE-2026-74746

Linux Kernel Netfilter Flowtable Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability has been resolved in the Linux kernel's netfilter component, which manages network traffic flows. The issue could allow an attacker to corrupt kernel memory, potentially leading to system instability or compromise. Its reachability is uncertain and depends on specific system configurations and

CVE advisoryCRITICAL

CVE-2026-74744

Linux Kernel IPvLAN Header Room Underflow Leading to Kernel Crashes.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's networking functionality could cause system instability or crashes. This occurs when the system fails to reserve sufficient space for network packet headers or trailers, potentially leading to memory corruption and kernel failures.

CVE advisoryCRITICAL

CVE-2026-74743

Linux Kernel macvlan Headroom Underflow and Crash Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's macvlan component may cause system instability or crashes due to incorrect memory management for packet headers. This could affect systems using specific tunneling or security features. Confirmation of macvlan usage and exposure is recommended.

CVE advisoryCRITICAL

CVE-2026-74737

Linux Kernel Ethernet Driver port_id Extraction Flaw Causes Crashes.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's Ethernet driver allows a kernel crash due to incorrect extraction of a MAC port ID from network packet metadata. This issue arises from improper handling of the Source Tag during packet reception. If reachable, this could lead to system instability and denial of service.

CVE advisoryCRITICAL

CVE-2026-54523

Kyverno Cross-Namespace Resource Creation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Kyverno's policy engine allows an authenticated user in one namespace to create or modify resources in other namespaces. This could lead to unauthorized changes and potential privilege escalation within the cloud-native platform.

CVE advisoryCRITICAL

CVE-2026-12717

Google Cloud BigQuery Data Transfer Service CData JDBC Remote Code Execution and Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An Improper Input Validation vulnerability in Google Cloud's BigQuery Data Transfer Service integration with the CData JDBC driver could allow an authenticated attacker to achieve remote code execution and escalate privileges using crafted JDBC connection string parameters. While this issue has been patched, understand

CVE advisoryCRITICAL

CVE-2026-77550

UniFi OS CRLF Injection Allows Network Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A network-accessible flaw in UniFi OS allows attackers to bypass authentication, potentially granting unauthorized access to devices. This vulnerability could impact network management functions due to the critical role UniFi OS devices often play. It is important to understand the presence and network exposure of thes

CVE advisoryCRITICAL

CVE-2026-77549

UniFi OS CRLF Injection Allows Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Improper Neutralization of CRLF Sequences vulnerability in UniFi OS may allow a network-accessible attacker to bypass authentication. This could grant unauthorized access to affected devices, impacting network management and control. Confirmation of device exposure and criticality is advised.

CVE advisoryCRITICAL

CVE-2026-18080

WordPress Plugin Unrestricted File Upload Leads to Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in a WordPress plugin for HR, accounting, and CRM, allowing unauthenticated attackers to upload and execute arbitrary PHP code via a crafted email attachment. This remote code execution is possible if the CRM module and IMAP Email Connect feature are enabled and configured, potentially i

CVE advisoryCRITICAL

CVE-2026-77545

UniFi OS Active Debug Code Privilege Escalation Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in UniFi OS allows a low-privilege attacker with network access to escalate privileges on affected devices under certain conditions. This could lead to elevated control over the device, posing a risk to operational security due to the potential compromise of network infrastructure.

CVE advisoryCRITICAL

CVE-2026-77539

UniFi OS Server Command Injection via Improper Input Validation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An Improper Input Validation vulnerability in UniFi OS Server could allow a privileged network attacker to execute commands on the host device. This could impact the device's integrity and potentially lead to broader network compromise. Readers should confirm if UniFi OS Server is in use and if affected configurations

CVE advisoryCRITICAL

CVE-2026-77534

UniFi OS Improper Access Control Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An Improper Access Control vulnerability in UniFi OS enables low-privilege network attackers to escalate privileges, potentially compromising network management devices. The scope of impact depends on an organization's specific UniFi OS deployment and network exposure.

CVE advisoryCRITICAL

CVE-2026-80235

EFence Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Arbitrary File Upload vulnerability exists in EFence, allowing unauthenticated remote attackers to upload and execute web shell backdoors. This can lead to arbitrary code execution on the server, potentially resulting in a complete system compromise. The primary concern is confirming the relevance and exposure of th

CVE advisoryCRITICAL

CVE-2026-77533

UniFi Protect Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An Improper Input Validation vulnerability in UniFi Protect Application could allow a low-privileged, network-connected attacker to execute commands on the host device. This may affect the integrity and availability of the application and system. The relevance and exposure of affected devices require confirmation.

CVE advisoryCRITICAL

CVE-2026-18431

WordPress Avada Theme and Fusion Builder Arbitrary File Write Leads to Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Avada theme and Fusion Builder plugin for WordPress have a critical vulnerability that allows unauthenticated attackers to write arbitrary files to the server. This can lead to remote code execution and complete site compromise when both components are installed and active, and specific administrator-authored conte

CVE advisoryCRITICAL

CVE-2026-58096

PPP Peer Allows Out-of-Bounds Write Due to Undersized Options

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the Point-to-Point Protocol daemon that could allow a malicious network peer to cause a system crash or potentially execute arbitrary code. This occurs due to undersized options triggering an out-of-bounds write. The relevance of this vulnerability depends on whether your environment uses PPP

CVE advisoryCRITICAL

CVE-2026-58095

PPP Endpoint Discriminator Buffer Overflow Leading to Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the PPP protocol's endpoint address handling could allow a malicious peer to cause a system crash or execute arbitrary code with root privileges. This occurs due to incorrect length calculations leading to a buffer overflow. It is uncertain if this technology is in use or exposed.

CVE advisoryCRITICAL

CVE-2026-15203

Danfoss Industrial Automation Debug Interface Improper Access Control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Improper access controls in Danfoss industrial automation, marine, and hybrid drive systems allow unauthorized users to read/write internal values, execute unsigned applications, and upload unsigned firmware. This vulnerability is present when debug and engineering interfaces are accessible, potentially leading to syst

CVE advisoryCRITICAL

CVE-2026-19632

TranslatePress Plugin Information Exposure Allows Administrator Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin used for website translation has a critical vulnerability that exposes administrator password reset URLs, enabling account takeover. This issue is exploitable by unauthenticated attackers under specific conditions involving automatic string saving and secondary language settings. Confirming plugin us