NVD disclosure day

Published threat advisories for August 28, 2026

CVE advisoryCRITICAL

CVE-2026-51663

TOTOLINK T6 Wireless Scan Exposure Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK routers allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results. This could expose information about connected wireless devices if the router's web interface is network-accessible. Readers should confirm if their organization u

CVE advisoryCRITICAL

CVE-2026-51661

TOTOLINK T6 Incorrect Access Control Exposes Port Forwarding Rules

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability in TOTOLINK T6 devices allows unauthenticated attackers to obtain port-forwarding rules by sending a crafted request, potentially exposing sensitive network configuration details. This issue is relevant for readers managing network devices that might be exposed to the internet.

CVE advisoryCRITICAL

CVE-2026-3627

IBM Concert SQL Injection Vulnerability Allows Database Manipulation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Concert has a SQL injection vulnerability that allows remote attackers to manipulate the back-end database. Attackers can view, add, modify, or delete information without requiring authentication or user interaction, potentially compromising data integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-19295

IBM Langflow OSS OS Command Execution via Crafted Flow Save.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS is vulnerable to arbitrary OS command execution when an authenticated user saves a specially crafted flow, allowing privilege escalation and bypassing security policies. This means an attacker could run unauthorized commands on the server. The reachability and business impact within our environment are

CVE advisoryCRITICAL

CVE-2026-19286

IBM Langflow OSS Remote Code Execution via Insecure Public Endpoint

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IBM Langflow OSS contains a critical vulnerability that could allow remote code execution through its public endpoint due to improper security restrictions. This could enable an attacker to run arbitrary code, potentially impacting system integrity. Confirming if your environment uses this technology and if the endpoin

CVE advisoryCRITICAL

CVE-2026-18527

IBM Administration Runtime Expert ARE GUI Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Administration Runtime Expert for i contains a vulnerability in its GUI component that could allow an unauthenticated remote attacker to gain elevated privileges on the IBM i system by executing actions under another user's profile. This could affect system data and services if the GUI is reachable.

CVE advisoryCRITICAL

CVE-2026-82329

JFrog Artifactory Authentication Bypass to Administrative Privileges

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

JFrog Artifactory contains an authentication weakness, potentially allowing an unauthenticated attacker with network access to gain administrative privileges. This could impact the integrity and availability of stored artifacts and build information. Organizations using Artifactory should verify its presence and assess

CVE advisoryCRITICAL

CVE-2026-82281

Kotaemon Conversation Hijacking Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Kotaemon, a chat application, has a vulnerability where it fails to properly check conversation ownership. This allows unauthorized users to access, read, delete, or rename other users' conversations if the application is reachable. It's important to determine if this technology is in use and exposed within your enviro

CVE advisoryCRITICAL

CVE-2026-82277

Argo Rollouts Dashboard Unauthenticated Mutating Operations

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Argo Rollouts dashboard has a vulnerability that allows unauthenticated attackers on the same network to perform critical operations on application rollouts. This could impact the availability of applications managed by Argo Rollouts. Uncertainty remains regarding the exact versions affected and the specific busine

CVE advisoryCRITICAL

CVE-2026-82266

Redpanda Admin API Unauthenticated Superuser Access Due to Default Configuration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Redpanda's Admin API, when accessible over the network without authentication, allows unauthenticated users to act as superusers, posing a critical risk. Attackers could exploit this to manage broker accounts, modify cluster configurations, and interfere with data replication, potentially disrupting services and compro

CVE advisoryCRITICAL

CVE-2026-82021

Hermes Agent MCP Catalog Supply Chain Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A supply chain vulnerability in the Hermes Agent's bundled catalog allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository. If this repository is referenced via a mutable branch, malicious code can propagate to any host installing the affected catalog entry without further o

CVE advisoryCRITICAL

CVE-2026-55634

Pimcore DataObject Import Endpoint Vulnerability Allows Code and SQL Injection.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authenticated user in Pimcore can inject PHP syntax into class definitions, leading to arbitrary code execution when objects are instantiated, and can also inject SQL into schema-changing statements. This vulnerability affects the class-definition import endpoint and is due to insufficient validation of field names.

CVE advisoryCRITICAL

CVE-2026-55559

Yamcs Instance Configuration Injection Leads to Remote Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Yamcs mission control framework allows attackers to inject commands into YAML configurations, potentially leading to arbitrary command execution with the service account's privileges. This affects deployments that do not properly escape input, and the risk depends on network accessibility and dep

CVE advisoryCRITICAL

CVE-2026-55511

Yamcs SQL Injection Leads to Arbitrary Java Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Yamcs mission control framework allows a user with specific privileges to execute arbitrary Java code on the server. This could lead to the exposure of sensitive mission data and credentials, or enable tampering with telemetry and denial of service. The issue is fixed in newer versions.

CVE advisoryCRITICAL

CVE-2026-55378

JS Recon Pull Request Command Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in JS Recon, a JavaScript enumeration tool, allows a remote user opening a pull request to execute commands on the GitHub Actions runner. This could lead to unauthorized access and control within the runner environment. It is important to verify if JS Recon is used in your CI/CD pipelines, as this could

CVE advisoryCRITICAL

CVE-2026-55248

plone.app.portlets RSS Feed Denial of Service and Network Probing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

plone.app.portlets is vulnerable to denial of service and information disclosure. An authenticated user can provide a malicious RSS feed URL to consume excessive memory, leading to denial of service. This vulnerability also allows for server-side requests to probe internal network services and can execute JavaScript in

CVE advisoryCRITICAL

CVE-2026-55247

Plone iCalendar Import Vulnerability Allows Internal Network Access Resource Exhaustion and Cross-Site Scripting

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Plone event management component has a vulnerability in its iCalendar import functionality that could allow a logged-in editor to access internal network resources, exhaust server resources causing a denial-of-service, or execute scripts in another user's browser. The vulnerability is related to insufficiently rest

CVE advisoryCRITICAL

CVE-2026-55220

Pimcore Hotspotimage Arbitrary Code Execution via Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Pimcore platform's Hotspotimage component allows an unauthenticated attacker to execute arbitrary code or write files by injecting malicious serialized data into a specific column. This occurs due to a lack of class restrictions during data deserialization, potentially leading to system compromis

CVE advisoryCRITICAL

CVE-2026-55068

free5GC NRF Instance Registration Validation Bypass Allows Control Plane Signaling Redirection.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An issue exists in free5GC, an open-source 5G core network implementation, allowing attackers with network access to impersonate network functions. This occurs because the NRF improperly handles network function registration profiles, potentially leading to the redirection of control-plane signaling, which could expose

CVE advisoryCRITICAL

CVE-2026-54755

Klever-Go Royalty Logic Flaw Allows Unbacked Asset Creation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Klever blockchain protocol's Go implementation allows for the creation of unbacked assets through crafted royalty values during asset transfers, marketplace purchases, or ITOs. This could impact the integrity of digital assets and the platform's economy. The issue is fixed in version 1.7.19.

CVE advisoryCRITICAL

CVE-2026-54754

Klever-Go Marketplace Settlement Allows Unbacked Currency Creation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Klever blockchain protocol's marketplace settlement could allow manipulation of referral and royalty percentages to create unbacked currency and corrupt token supply integrity. This issue arises during purchase settlements where the system may credit buyers with more currency than paid, impacting

CVE advisoryCRITICAL

CVE-2026-54745

Kubeflow Pipelines Unauthenticated Server-Side Request Forgery Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in Kubeflow Pipelines allows unauthenticated attackers to access internal services and sensitive data by exploiting a proxy route. This could expose cloud credentials, APIs, and other internal endpoints to unauthorized read or modification. Confirming the reachability and cri

CVE advisoryCRITICAL

CVE-2026-51657

TOTOLINK T6 Router Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability in TOTOLINK routers allows unauthenticated attackers to obtain syslog configuration details. This could potentially expose sensitive network information, and the vulnerability is reachable via crafted POST requests to the device's web interface.

CVE advisoryCRITICAL

CVE-2026-51646

TOTOLINK T6 Parental Control Rule Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control flaw in TOTOLINK T6 routers permits unauthenticated attackers to retrieve parental control rules by sending a crafted request to the device's web interface. This vulnerability could expose network usage policies. Confirming the presence and network exposure of these devices is advised.

CVE advisoryCRITICAL

CVE-2026-51645

TOTOLINK T6 Router Administrative Credentials Disclosure Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control flaw in TOTOLINK routers allows unauthenticated attackers to obtain administrative usernames by sending a crafted POST request. This could lead to unauthorized access to device configurations, making it important to determine if any affected devices are present and exposed within your environment.

CVE advisoryCRITICAL

CVE-2026-51643

TOTOLINK T6 NTP Configuration Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in a TOTOLINK router allows unauthenticated attackers to obtain NTP configuration and current time data. Attackers can exploit this by sending a crafted request to a specific endpoint. This could be relevant if such devices are in use and exposed on the network.

CVE advisoryCRITICAL

CVE-2026-51636

TOTOLINK T6 ACL Rule Exposure via Unauthenticated Request

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability exists in a TOTOLINK router function that allows unauthenticated attackers to obtain Wi-Fi ACL rules. Reachable via a web-based interface, this could expose sensitive Wi-Fi configuration data. Organizations should confirm if this technology is in use and exposed to understand p

CVE advisoryCRITICAL

CVE-2026-51628

TOTOLINK T6 WPS PIN Generation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability in TOTOLINK routers allows unauthenticated attackers to generate and retrieve new Wi-Fi Protected Setup (WPS) PINs. This could potentially lead to unauthorized network access if the affected function is reachable. Confirming device relevance and exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-51622

TOTOLINK T6 Router WAN Configuration Exposure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An incorrect access control vulnerability exists in a TOTOLINK router function that retrieves WAN configuration data. Attackers can exploit this by sending a crafted POST request to the router's web interface, potentially exposing sensitive network setup details to unauthenticated users. This could lead to further netw

CVE advisoryKnown Exploit

CVE-2026-82078

PaperCut MF/NG Unsafe Dynamic Class Loading Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unsafe dynamic class loading vulnerability exists in PaperCut MF and NG database connection utilities, allowing for arbitrary Java bytecode execution on the server if an attacker can manipulate system configuration. This could lead to the compromise of the PaperCut server if the vulnerability is reachable and releva

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-81578

PaperCut MF NG Web Interface Access Control Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper access control vulnerability in PaperCut MF and NG's web management interface allows unauthenticated remote attackers to modify system configurations by triggering backend actions before access validation. This could enable unauthorized changes to critical settings if the software is relevant and exposed.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-37236

gRPC Gateway Incorrect Access Control via Method Override Header.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in gRPC-Gateway allows attackers to bypass method-based security controls. By sending a POST request with a specific content type and an overridden HTTP method header, an attacker can force the application to process the request with an arbitrary method, potentially leading to

CVE advisoryCRITICAL

CVE-2026-82244

Budibase Plugin Handling Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Budibase software allows authenticated administrators to execute arbitrary code by uploading malicious plugins, potentially exposing sensitive data. The server evaluates plugin JavaScript without proper isolation, enabling attackers to exfiltrate environment variables and credentials. This i

CVE advisoryCRITICAL

CVE-2026-42007

Sieve Editheader Use-After-Free in Mail Delivery

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in mail editing code allows an attacker with valid credentials to cause memory corruption during mail delivery, potentially leading to crashes or arbitrary code execution. The Sieve editheader extension should be disabled. The exact impact is uncertain as no public exploits are known.

CVE advisoryCRITICAL

CVE-2026-18918

Eclipse Lyo OAuth Authorization Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Eclipse Lyo's OAuth server has a critical flaw where authorization checks can be bypassed, allowing provisional clients to be used immediately without approval. This impacts applications using specific Lyo authorization filters when 2-legged authentication is supported. Systems employing this framework should be review

CVE advisoryCRITICAL

CVE-2026-80714

Linux kernel IPVS connection flag propagation vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's IPVS component could allow improper handling of connection flags, potentially leading to memory corruption and system instability. The issue arises from how synced connections interact with a specific flag, causing stale data pointers. While the exposure is considered low, it's imp

CVE advisoryCRITICAL

CVE-2026-80694

Linux Kernel MTK Ethernet driver crash vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's network driver for certain MediaTek SoCs could lead to a system crash if network interrupt handling is polled. This issue arises from incorrect data passing between internal functions, potentially impacting system availability. Confirming if affected kernel configurations are in us

CVE advisoryCRITICAL

CVE-2026-80674

Linux Kernel NTFS Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel's NTFS driver has a vulnerability where it fails to validate resident attribute lists, potentially allowing crafted data to cause out-of-bounds reads. This could impact system data integrity and availability when interacting with a specially malformed NTFS filesystem.

CVE advisoryCRITICAL

CVE-2026-80673

Linux Kernel NTFS Slab Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's NTFS driver can lead to an out-of-bounds read when processing specially crafted attribute lists on a disk image. This could potentially result in information disclosure or system instability if an attacker can control the mounting of such a filesystem. The risk is mitigated by the

CVE advisoryCRITICAL

CVE-2026-80668

Linux Kernel netfilter Expectation Handling Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Linux kernel's netfilter component related to how it manages network connection tracking expectations. The issue has been resolved by updating the system to use a garbage collection worker approach, which implicitly addresses a race condition that could allow an expectation to access relea

CVE advisoryCRITICAL

CVE-2026-80634

Linux Kernel Netfilter Flowtable Stack Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's netfilter component may allow an attacker to read sensitive system memory through a malformed bridge VLAN configuration. The issue stems from an integer underflow during VLAN untagging, potentially leading to an out-of-bounds stack read. This could affect system integrity and may l

CVE advisoryCRITICAL

CVE-2026-80617

Linux Kernel Airoha Driver Heap Buffer Overflow.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory allocation error in the Linux kernel's Airoha network driver can lead to a heap buffer overflow, potentially causing a system crash. This vulnerability can be triggered by specific network traffic, impacting system stability. The primary concern is to determine if this driver is active in the environment.

CVE advisoryCRITICAL

CVE-2026-80612

Linux Kernel LWT Encapsulation Metadata Overwrite Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's networking component could allow for the corruption or loss of packet metadata during light-weight tunnel (LWT) encapsulation, potentially causing unpredictable network behavior. This issue arises from how metadata is handled when packets are forwarded and encapsulated, and while i

CVE advisoryCRITICAL

CVE-2026-80609

Linux Kernel qede Out-of-Bounds Read Leads to Data Corruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's qede network driver could allow an attacker to access or modify kernel memory by sending crafted network traffic. This could lead to system instability or compromise. The issue has been fixed, but confirmation of its presence and potential impact in your environment is needed.

CVE advisoryCRITICAL

CVE-2026-80603

Linux Kernel netfilter IRC Off-by-One Out-of-Bounds Read

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's netfilter component allows for an out-of-bounds read when parsing IRC DCC commands, potentially leading to incorrect connection tracking information. This issue could be exploited if a system processes IRC traffic. Uncertainty exists regarding the specific impact and exploitability

CVE advisoryCRITICAL

CVE-2026-80600

Linux Kernel batman-adv Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Linux kernel's batman-adv module could allow an attacker to trigger a use-after-free condition when network buffers are reallocated. This flaw may impact system stability and data integrity. While its direct relevance to typical business operations may be limited, understanding its poten

CVE advisoryCRITICAL

CVE-2026-78032

SOY CMS Deserialization Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SOY CMS could permit arbitrary code execution with web server privileges. This occurs because the system deserializes untrusted data, potentially allowing attackers to run unauthorized code on the server. It's important to determine if SOY CMS is in use and exposed.

CVE advisoryCRITICAL

CVE-2026-76581

WPMU DEV Dashboard Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in the WPMU DEV Dashboard plugin allows unauthenticated attackers to hijack administrator sessions. Exploitation requires the plugin and its Hub SSO feature to be enabled and configured for administrator mapping. This could result in unauthorized administrator access to WordPress

CVE advisoryCRITICAL

CVE-2026-82090

Pocket External HTML Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Pocket application allows external HTML injection through its "Save to Pocket" feature, potentially enabling unauthorized JavaScript execution and alteration of application state. This could impact user interactions and the application's behavior when a user saves specific web content.

CVE advisoryCRITICAL

CVE-2026-82082

NUMail OS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Green-Computing's NUMail has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary commands on the server. This could lead to system compromise if the vulnerable service is reachable. Assess if this technology is used and exposed within our environment.

CVE advisoryCRITICAL

CVE-2026-19315

WatchGuard Fireware OS iked Type Confusion Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A type confusion vulnerability in WatchGuard Fireware OS's `iked` process allows unauthenticated remote attackers to execute arbitrary code via specially crafted network traffic. Because firewalls are network edge devices and the `iked` process handles incoming traffic, this vulnerability is likely exposed externally,

CVE advisoryCRITICAL

CVE-2026-19313

WatchGuard Fireware OS iked Heap Overflow Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical heap overflow vulnerability exists in WatchGuard Fireware OS, potentially allowing unauthenticated remote attackers to execute arbitrary code by sending crafted network traffic. This affects the iked process, which handles network connections, and could impact the integrity and availability of network edge d

CVE advisoryCRITICAL

CVE-2026-13086

WatchGuard Fireware OS epm Service Stack Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow in the epm service of WatchGuard Fireware OS's deprecated Mobile Security feature allows unauthenticated remote attackers to execute arbitrary code if the service is reachable. This could impact the confidentiality and integrity of network security operations. Confirmation of usage and exp

CVE advisoryCRITICAL

CVE-2026-78239

Xiiaozet LK100W Unauthenticated Management Function Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Xiiaozet LK100W devices have a critical vulnerability allowing unauthenticated remote attackers to enable administrative services, potentially granting unauthorized access. This issue is relevant for technical readers and security leaders to understand the risk of exposed management functions.

CVE advisoryCRITICAL

CVE-2026-76179

Ebyte Gateway Authentication Token Improper Protection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products, potentially allowing an attacker to impersonate users and gain unauthorized access to device management functions. This issue stems from insufficient protection of authentication tokens used by the web management int

CVE advisoryCRITICAL

CVE-2026-75337

Yu AI Code Mother Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical path traversal vulnerability in Yu AI Code Mother's static resource interface allows anonymous attackers to read files outside the preview root directory. This occurs because user-controlled paths are concatenated without normalization. The main concern is confirming relevance and exposure of this vulnerabil

CVE advisoryCRITICAL

CVE-2026-73125

Ebyte Device Web Interface Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Ebyte device web management interface, allowing unauthenticated remote attackers to access sensitive configuration information, modify settings, or disrupt operations. This lack of consistent authentication enforcement means a reachable interface could be compromised. Understandin

CVE advisoryCRITICAL

CVE-2026-71187

Ebyte Device Authentication Bypass Grants Administrative Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in Ebyte devices, enabling unauthenticated users to gain administrative control by replicating the device's client-side authentication logic. This allows attackers to bypass security measures and obtain administrative access remotely. The primary concern is confirming the p

CVE advisoryCRITICAL

CVE-2026-69658

MQTT Cleartext Transmission Exposes Credentials and Control Traffic

Halo Surface Signal: 3 out of 5 — possibly public-facing.

MQTT credentials and control traffic are transmitted unencrypted, allowing network attackers to intercept sensitive information. This could enable unauthorized device impersonation and disruption of messaging functions. The relevance and exposure of MQTT deployments to network-level attackers need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-68929

FastGPT WeChat Share Channel Vulnerability Allows Bot Hijacking

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can hijack FastGPT WeChat share channels by exploiting missing authorization, leading to bot disruption and potential exposure of private responses. This issue affects the platform's public-facing AI applications and their integrations.

CVE advisoryCRITICAL

CVE-2026-50152

Ceph Monitor Authorization Bypass Exposes Secrets and Enables Full Cluster Compromise

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Ceph distributed storage platform has a vulnerability where a user with limited read-only access can exploit a Monitor authorization bypass to read sensitive secrets, including disk encryption passphrases and administrative SSH keys. This could lead to a full compromise of the storage cluster and its hosts.

CVE advisoryCRITICAL

CVE-2026-18717

ASE2000 Improper Certificate Validation Allows Impersonation and Communication Interception.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in ASE2000 allows an attacker to impersonate a trusted peer, bypass security, and potentially read or alter protected communications. This impacts the confidentiality and integrity of sensitive data transmitted by the technology. Confirmation of ASE2000's presence and network exposure is necessary to as