NVD disclosure day

Published threat advisories for August 29, 2026

CVE advisoryCRITICAL

CVE-2026-15369

Custom User Registration Fields for WooCommerce Privilege Escalation via Store API.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Custom User Registration Fields for WooCommerce plugin contains a privilege escalation vulnerability. An unauthenticated attacker could exploit this by sending a crafted request to the WooCommerce Store API during checkout, allowing them to assign themselves an administrator role if a specific plugin setting is ena

CVE advisoryCRITICAL

CVE-2026-82466

Rodauth Authentication Bypass via WebAuthn Login.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Rodauth contains an authentication bypass vulnerability where logged-in users can impersonate any account by exploiting improper account resolution logic in the webauthn_login route. This could allow unauthorized access to user data and system functions. Confirming relevance and exposure is key.

CVE advisoryCRITICAL

CVE-2026-82460

Cloud Commander Directory Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in Cloud Commander allows attackers to access files outside authorized directories by exploiting path normalization failures in REST and markdown endpoints. This could lead to unauthorized reading, writing, moving, or copying of sensitive data, impacting system integrity and access c

CVE advisoryCRITICAL

CVE-2026-82456

Argo CD MCP Authentication Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Argo CD MCP where the HTTP transport binds to all network interfaces and accepts sessions without credentials if ARGOCD_API_TOKEN is configured, allowing attackers to invoke full tool functionality and modify resources. This could enable unauthorized creation of applications, request syncs, an

CVE advisoryCRITICAL

CVE-2026-82454

Omnivore API Authentication Bypass via Apple Sign-In Token Verification.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Omnivore API has an authentication bypass vulnerability in its Apple sign-in token verification. This could allow an attacker to impersonate any user with an Apple-linked account by forging a token. It's important to determine if this authentication method is used and if it's reachable.

CVE advisoryCRITICAL

CVE-2026-82452

Rust-IoT-Platform Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in the rust-iot-platform's REST API, where unauthenticated attackers can access unprotected endpoints to create, update, list, retrieve, and delete user accounts without valid credentials. This impacts IoT platforms managing user data and access, making it crucial to confir

CVE advisoryCRITICAL

CVE-2026-82448

Shinobi Child Node Service Hardcoded Key Allows Arbitrary Database Queries.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Shinobi's child node service has a hardcoded key that allows unauthenticated attackers to execute arbitrary database queries, potentially reading or modifying user and camera data. Confirmation of the technology's use and its network exposure is critical to understanding the risk.

CVE advisoryCRITICAL

CVE-2026-14494

Sigma Forms Pro for WordPress Unrestricted File Upload Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Sigma Forms Pro WordPress plugin contains a critical vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. This occurs due to insecure file upload handling, which bypasses security validations, potentially enabling the execution of malicious files through common form submissio

CVE advisoryCRITICAL

CVE-2026-80725

Linux Kernel GRO BIG TCP Packet Aggregation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's network packet aggregation could allow crafted network traffic to cause out-of-bounds memory writes. This impacts older kernel versions and may lead to system instability if reachable.A vulnerability in the Linux kernel's network packet aggregation could allow crafted network traff

CVE advisoryCRITICAL

CVE-2026-77012

爱采集 WordPress Plugin Arbitrary File Read and Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a WordPress plugin allows unauthenticated attackers to read arbitrary server files, make unauthorized requests, and write content outside of the intended directory. This occurs because the plugin improperly validates URLs and uses a hardcoded default secret. Understanding if the plugin is in

CVE advisoryCRITICAL

CVE-2026-16947

Total Processing Card Payments for WooCommerce Path Traversal and Response Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit a vulnerability in the Total processing card payments for WooCommerce WordPress plugin to redirect requests and forge responses, potentially exposing merchant payment gateway credentials and marking arbitrary orders as paid without actual payment. The affected technology is a plu

CVE advisoryCRITICAL

CVE-2026-16259

Uix UserCenter WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated flaw in the Uix UserCenter WordPress plugin allows attackers to take over accounts by forging tokens to alter user credentials. This vulnerability could enable unauthorized access and control over administrator accounts on public-facing WordPress sites.

CVE advisoryCRITICAL

CVE-2026-10522

MemberHero WordPress Plugin Account Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the MemberHero WordPress plugin allows unauthenticated attackers to register as administrators, potentially leading to a full site takeover. While a fix was advertised, it is incomplete, and no fully resolved version is currently available. Mitigation involves deactivating and removing the plugin or