NVD disclosure day

Published threat advisories for August 31, 2026

CVE advisoryCRITICAL

CVE-2026-82971

QVidium Opera11 CGI Script Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in a CGI script within QVidium Opera11. Exploitable remotely, this flaw allows attackers to execute arbitrary system commands by manipulating an `ipaddr` argument, potentially compromising system integrity and data. As the vendor is defunct and offers no support, organi

CVE advisoryCRITICAL

CVE-2026-82226

Tickera PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in the Tickera event ticketing system. If reachable, this flaw could allow an attacker to execute arbitrary code, potentially impacting system confidentiality, integrity, and availability. Confirming the use and exposure of this system is essential.

CVE advisoryCRITICAL

CVE-2026-81780

Hash Form Unauthenticated Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated arbitrary file upload vulnerability exists in Hash Form, a technology for managing online submissions. Attackers could exploit this to upload malicious files, potentially leading to system compromise and unauthorized access to data. Confirming its presence and relevance is crucial.

CVE advisoryCRITICAL

CVE-2026-81779

Newspapers X Improper Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper input validation vulnerability in the Newspapers X theme allows for the potential implantation of malicious software. This could affect the integrity and availability of websites using the affected theme versions, with a wide network attack surface.

CVE advisoryCRITICAL

CVE-2026-81763

Unauthenticated SQL Injection in Throws SPAM Away 3.8.2 and earlier.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Throws SPAM Away, allowing unauthenticated attackers to access or manipulate database content via network requests. This could impact data integrity and service availability. Confirming its presence and reachability is crucial for affected systems.

CVE advisoryCRITICAL

CVE-2026-81756

Smart Marketing SMS and Newsletters Forms Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Smart Marketing SMS and Newsletters Forms plugin. Attackers can exploit this to inject malicious code, potentially leading to unauthorized access to or modification of sensitive data. This issue is relevant to internet-facing marketing plugins.

CVE advisoryCRITICAL

CVE-2026-81293

Unauthenticated SQL Injection in WP Data Access Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WP Data Access component, potentially allowing attackers to access or modify sensitive database information. This issue is concerning because it can be reached via the network without authentication, posing a risk to data integrity and system availability in

CVE advisoryCRITICAL

CVE-2026-38577

Tenda HG21 V4.0.0-260302 Hardcoded Admin Credentials Allow Root Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Tenda routers, allowing unauthorized network access to gain root control through hardcoded administrator credentials. This could compromise device confidentiality, integrity, and availability. Given that routers are often internet-facing, it's important to determine if these devices a

CVE advisoryCRITICAL

CVE-2026-51738

TOTOLINK T6 Router Unauthorized Configuration Reset and Reboot

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated network request can reset TOTOLINK router configurations and reboot the device, potentially disrupting services. This vulnerability resides in improper access controls within a specific function. Confirming the presence and exposure of affected devices is crucial.

CVE advisoryCRITICAL

CVE-2026-51734

TOTOLINK T6 Mesh Slave Update Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in TOTOLINK routers could allow unauthenticated attackers to trigger mesh slave updates. Attackers can exploit this by sending a crafted POST request, potentially impacting device integrity and availability. Confirming affected devices and assessing network exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-51733

TOTOLINK T6 Wi-Fi Schedule Removal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability in the firmware of TOTOLINK T6 routers allows unauthenticated attackers to remove Wi-Fi schedule entries. This could disrupt network operations by altering Wi-Fi availability. The relevance of this issue depends on whether the affected technology is in use and exposed.

CVE advisoryCRITICAL

CVE-2026-53552

Goploy Project File Manipulation Leading to RCE.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Goploy, an open-source deployment system, has a vulnerability that allows a user with manager privileges to manipulate files and critical project configurations in any project, potentially leading to remote code execution during the next deployment. This issue impacts core deployment operations and could result in a br

CVE advisoryCRITICAL

CVE-2026-79748

MCPHub Unauthenticated Arbitrary Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MCPHub, a system for orchestrating MCP servers, has a vulnerability allowing authenticated users to execute arbitrary commands. This occurs because the system does not properly validate command and argument fields when creating or updating server configurations. An attacker could exploit this by submitting a malicious

CVE advisoryCRITICAL

CVE-2026-51728

TOTOLINK T6 Firmware Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability exists in a router's firmware upload function, potentially allowing attackers to remotely upload malicious firmware. This could lead to unauthorized control or modification of the device, impacting its confidentiality, integrity, and availability. It is important to assess if any affect

CVE advisoryCRITICAL

CVE-2026-51726

TOTOLINK T6 Parental Control Rule Removal Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in TOTOLINK routers allows unauthenticated attackers to remove parental control rules via a crafted request. This could enable bypassing network restrictions. Confirm if this technology is in use and exposed within your environment.

CVE advisoryCRITICAL

CVE-2026-51725

TOTOLINK T6 Clock Tampering Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK routers allows unauthenticated attackers to modify the device clock via a crafted POST request, potentially affecting time-sensitive operations or logs. This issue is relevant to the device's clock synchronization feature, which is accessible over the network.

CVE advisoryCRITICAL

CVE-2026-51724

TOTOLINK T6 Improper Access Control Allows Unauthenticated QoS Rule Removal

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Improper access control in TOTOLINK routers allows unauthenticated attackers to remove Quality of Service rules via a crafted request, potentially disrupting network traffic management. The primary concern is confirming if this technology is in use within your environment.

CVE advisoryCRITICAL

CVE-2026-51723

TOTOLINK T6 CGI Module Installation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit a critical access control vulnerability in TOTOLINK T6 routers by installing custom CGI modules. If reachable, this could allow unauthorized code execution, potentially leading to altered device behavior or unauthorized access. Confirming if your organization uses this technology

CVE advisoryCRITICAL

CVE-2026-51722

TOTOLINK T6 Wi-Fi Repeater Unauthorized Upstream Network Redirection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control flaw in TOTOLINK Wi-Fi repeaters allows unauthenticated attackers to redirect the device to an attacker-controlled network via a crafted request. This could impact network traffic integrity and confidentiality if the devices are accessible. Confirming device deployment and network exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-51720

TOTOLINK T6 Router Firewall Rule Removal Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can remove firewall filter rules on TOTOLINK routers by sending a crafted request. This could weaken network defenses, potentially allowing unauthorized access or manipulation. The relevance and exposure of TOTOLINK routers should be confirmed.

CVE advisoryCRITICAL

CVE-2026-73819

Ebyte Configuration Utility Allows Unauthenticated Administrative Access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated adjacent network attacker can exploit a vulnerability in the Ebyte product's vendor configuration utility. This flaw allows modification of critical settings or access credentials without proper identity verification, potentially hindering legitimate administrator control.

CVE advisoryCRITICAL

CVE-2026-51717

TOTOLINK T6 Router Unauthorized Operating Mode Change Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK devices allows unauthenticated attackers to change the device's operating mode by sending a crafted request. This could impact network configuration and security if the device is reachable. Confirm relevance and assess exposure.

CVE advisoryCRITICAL

CVE-2026-51711

TOTOLINK T6 Incorrect Access Control in setWiFiWpsStart

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated network attacker can exploit an incorrect access control vulnerability in a TOTOLINK router's Wi-Fi Protected Setup function. This could allow them to initiate a wireless pairing window, potentially leading to unauthorized access. The primary concern is determining if affected devices are exposed and

CVE advisoryCRITICAL

CVE-2026-51710

TOTOLINK T6 Parental Controls Vulnerability Allows Unauthenticated Rule Alteration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can alter parental control settings on a TOTOLINK router by sending a crafted request to a CGI interface. This could impact network access policies for connected devices. Readers should determine if affected devices are in use within their environment.

CVE advisoryCRITICAL

CVE-2026-51709

TOTOLINK T6 Wi-Fi Configuration Reconfiguration Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can reconfigure primary Wi-Fi settings on TOTOLINK routers by sending a crafted request. This vulnerability, due to incorrect access controls, could allow unauthorized changes to network configurations. Organizations should confirm if these routers are in use and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-51705

TOTOLINK T6 Mesh Rename Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in TOTOLINK T6 routers allows attackers to rename mesh network entries by sending a crafted request. This could enable unauthorized control or disruption of network configurations. Its relevance depends on the reachability and exposure of affected devices.

CVE advisoryCRITICAL

CVE-2026-51701

TOTOLINK T6 Router Access Control Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK devices allows unauthenticated attackers to change device access control settings by sending a crafted request. This could enable unauthorized modification of network access rules. This issue is relevant if such devices are used and potentially exposed.

CVE advisoryCRITICAL

CVE-2026-51699

TOTOLINK T6 Router Exposed via Access Control Flaw

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in a router's configuration function allows unauthenticated attackers to potentially expose internal hosts. This could enable unauthorized access to network devices if the affected technology is reachable. Readers should confirm the relevance and exposure of this technology within their

CVE advisoryCRITICAL

CVE-2026-51698

TOTOLINK T6 Browsing Policy Alteration Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in TOTOLINK T6 devices allows unauthenticated attackers to alter browsing policies via crafted network requests. This could potentially impact internet access for users on affected networks. The vendor has not yet released a fix, and the relevance and exposure of this issue need to be co

CVE advisoryCRITICAL

CVE-2026-51152

Server-Side Request Forgery in QD /har/test Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in the /har/test endpoint allows unauthenticated attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. This could potentially lead to unauthorized access or exposure of sensitive information. It is importa

CVE advisoryCRITICAL

CVE-2026-82970

WP Legal Pages Cookie Notice Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin permits the upload of malicious files. This could enable an unauthenticated attacker to compromise website data or services. Determining the plugin's presence on internet-facing systems is a priority.

CVE advisoryCRITICAL

CVE-2026-66047

ProfilePress Plugin Unauthenticated Arbitrary Plugin Installation RCE.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in a WordPress plugin allows unauthenticated attackers to install and activate arbitrary plugins, potentially leading to remote code execution. This is achieved by exploiting a weak token to trigger a silent plugin installation via a controlled URL. The primary risk is the compromise of the web

CVE advisoryCRITICAL

CVE-2026-59111

DIA eObčanka-Identifikace MacOS Command Injection via Custom URL Scheme

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the eObčanka-Identifikace application on MacOS allows for OS command injection via a custom URL scheme. An attacker could trick a user into opening a malicious URL, leading to the execution of arbitrary commands on the user's system. This is a concern if the application is installed and users interac

CVE advisoryCRITICAL

CVE-2026-51697

TOTOLINK T6 Incorrect Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can alter IPTV service configuration on TOTOLINK routers by sending a crafted request to a specific script. This could disrupt or redirect the IPTV service. Confirming the presence and network exposure of affected devices is crucial for security.

CVE advisoryCRITICAL

CVE-2026-51696

TOTOLINK T6 RoutersetPortForwardRules Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability exists in TOTOLINK routers that allows unauthenticated attackers to expose internal services by sending a crafted request. This could make internal network services accessible over the internet. Readers should confirm if their network is affected and understand the potential relevance to

CVE advisoryCRITICAL

CVE-2026-51692

TOTOLINK T6 Guest Wi-Fi Access Control Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can modify guest Wi-Fi settings on a TOTOLINK T6 device by sending a crafted request. This could impact the availability or security of the guest network. Confirm if this device is deployed within your network and if it is exposed to external access.

CVE advisoryCRITICAL

CVE-2026-51690

TOTOLINK T6 Access Control Vulnerability Allows Upstream Provisioning Alteration

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can alter upstream provisioning and connectivity by sending a crafted request to a function in TOTOLINK routers. This could impact network configuration and internet access if the device's web interface is reachable via the internet. Confirming device presence and external reachability is ke

CVE advisoryCRITICAL

CVE-2026-51689

TOTOLINK T6 Firmware Upgrade Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability exists in a function that handles firmware upgrades in TOTOLINK routers. This flaw could allow unauthenticated attackers to remotely alter the firmware upgrade process by sending a crafted request, potentially leading to unauthorized device modifications. It is important to con

CVE advisoryCRITICAL

CVE-2026-51684

TOTOLINK T6 Router Storage Configuration Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can exploit a network vulnerability in TOTOLINK routers by sending a crafted request to change storage configurations, potentially impacting service confidentiality, integrity, and availability. Given the common deployment of these devices at network edges and the potential for remote access

CVE advisoryCRITICAL

CVE-2026-51681

TOTOLINK T6 Router WAN Administration Exposure Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in TOTOLINK networking devices may allow unauthenticated attackers to expose WAN-side administration settings. This could potentially allow unauthorized modification of network configurations, impacting network security. Confirming the presence and exposure of this technology is recommen

CVE advisoryCRITICAL

CVE-2026-51680

TOTOLINK T6 Router LED Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect access control vulnerability in a TOTOLINK router's `setLedCfg` function allows unauthenticated attackers to modify LED behavior via a crafted POST request. This could lead to unexpected device behavior or be used as part of a larger attack, impacting network edge device security.

CVE advisoryCRITICAL

CVE-2026-51679

TOTOLINK T6 Router Unauthenticated Administrator Password Change

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated access control vulnerability in TOTOLINK routers allows attackers to change the administrator password via a crafted POST request. This could lead to unauthorized control over the router's settings and potentially impact network security. The presence and exposure of affected devices within an organi

CVE advisoryCRITICAL

CVE-2026-51676

TOTOLINK T6 Access Control Vulnerability Allows Policy Alteration.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can alter access-device policies on TOTOLINK T6 devices by sending a crafted POST request. This vulnerability could allow unauthorized changes to network access control, potentially disrupting operations or facilitating unauthorized access. Readers should confirm relevance and exposure for t

CVE advisoryCRITICAL

CVE-2026-51675

TOTOLINK T6 Router Unauthenticated Uplink Configuration Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An access control vulnerability in TOTOLINK routers could allow unauthenticated attackers to reconfigure uplink settings by sending a crafted request. This could impact internet connectivity or allow unintended network traffic paths. Verify if your environment uses affected devices and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-51672

TOTOLINK T6 Roaming Configuration Access Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can obtain the roaming enablement flag by sending a crafted request to the router's management interface. This could expose sensitive network configuration details. Readers should confirm if affected TOTOLINK equipment is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-51670

TOTOLINK T6 Router Access Control Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK routers allows unauthenticated attackers to query slave upgrade status and potentially affect upgrade bookkeeping by sending a crafted POST request to the device's web interface. This could lead to unauthorized information disclosure and manipulation of system proce

CVE advisoryCRITICAL

CVE-2026-51669

TOTOLINK T6 Router Configuration Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in TOTOLINK routers allows unauthenticated attackers to obtain sensitive network configuration details via a crafted request. This could expose pairing and mesh-slave configurations, which is a concern for internet-facing network devices. Technical readers and security-aware leaders should conf

CVE advisoryCRITICAL

CVE-2026-82695

Tenda AC18 Telnet Missing Authentication Remote Exploit

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Tenda network devices' Telnet handler, allowing unauthenticated remote access. An exploit is publicly available, potentially enabling attackers to gain control over the device. This issue is relevant if Tenda devices are in use and exposed to networks.A critical vulnerability exists i

CVE advisoryCRITICAL

CVE-2026-82693

Tenda AC1206 Missing Authentication in Web UI Telnet Function

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Tenda routers, allowing unauthenticated remote attackers to bypass authentication for the Web UI's Telnet function. Exploitation could lead to unauthorized access and control of the device. The exploit is publicly known, increasing risk.

CVE advisoryCRITICAL

CVE-2026-82860

Hulumi Policies IAM Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the @hulumi/policies library allows for bypassing administrator policy guardrails by crafting policy paths that circumvent evaluation. This could impact systems relying on these policies for access management. Uncertainty exists regarding how an attacker could reach and trigger this vulnerability.

CVE advisoryCRITICAL

CVE-2026-82858

Hulumi Drift Unsafe Execute Plan Acceptance Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The @hulumi/drift technology, when accepting externally supplied execute plans without sufficient validation, presents a risk. Attackers can provide malicious plans that bypass security checks, potentially leading to unsafe reconciliation operations. It is important to determine if this technology is in use and if it p

CVE advisoryCRITICAL

CVE-2026-82857

Hulumi Privilege Escalation Vulnerability in Weekly Integration IAM Policy

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A privilege escalation vulnerability exists in hulumi's weekly integration IAM policy. If reachable, an attacker with documented principal access could create persistent, higher-privilege roles in sandbox accounts by performing role lifecycle operations without sufficient boundary restrictions.

CVE advisoryCRITICAL

CVE-2026-82856

@hulumi/policies IAM Condition Operator Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects the `@hulumi/policies` library, which fails to validate AWS IAM condition operators in GitHub OIDC trust policies. This allows attackers to potentially hide wildcard conditions and bypass security guardrails. The relevance and exposure of this library in your environment need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-82855

Hulumi Policies Evidence Validation Bypass Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An evidence validation bypass vulnerability exists in `@hulumi/policies`, allowing attackers to circumvent security checks by submitting unrelated compliant evidence. This could weaken security guardrails for cloud resources, potentially leading to the deployment of insecure configurations. The relevance and exposure o

CVE advisoryCRITICAL

CVE-2026-19410

Google Cloud Build Incorrect Authorization Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An Incorrect Authorization vulnerability in Google Cloud Build's GitHub Trigger Comment Control allowed remote attackers to execute unreviewed code in the build environment via webhook suppression. This issue affects internal development and automation workflows, and while patched, understanding potential exposure is c

CVE advisoryCRITICAL

CVE-2026-58574

Dell PowerStore Missing Authentication Information Disclosure Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Dell PowerStore systems have a critical vulnerability where missing authentication on a restricted management interface could allow an unauthenticated network attacker to read sensitive internal system information and credentials. Exploitation could lead to full administrative access to the storage array.

CVE advisoryHIGH

CVE-2026-77956

Ash AI Prompt Injection Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in ash_ai allows unauthenticated attackers to execute arbitrary Elixir code on the server by manipulating prompt content, which is improperly evaluated as code before AI model requests are processed. This could lead to server-side code execution if prompt actions incorporate attacker-controlled data. It