NVD disclosure day

Published threat advisories for September 1, 2026

CVE advisoryCRITICAL

CVE-2026-84480

WWBN AVideo Password Recovery Token Bypass Allows Indefinite Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in WWBN AVideo allows attackers to indefinitely reset account passwords using expired recovery tokens, potentially granting unauthorized, permanent access to user accounts. The platform's password recovery functionality, if exposed to the internet, makes this threat reachable. This issue should be a con

CVE advisoryCRITICAL

CVE-2026-84479

WWBN AVideo Authentication Bypass via User Agent Header

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WWBN AVideo's login security controls are vulnerable because they rely solely on the client-supplied User-Agent header. An attacker can bypass authentication, including multi-factor authentication and brute-force protections, by sending a specific User-Agent string. This could allow unauthorized access to the system.

CVE advisoryCRITICAL

CVE-2026-84637

Thunderbird Calendar Invitations Execute Local Files Via File URI Attachments.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Thunderbird allows malicious calendar invitations to execute local or network programs on Windows by bypassing attachment protections through file URI attachments. This could occur if the new invitation display is enabled, potentially disguising the attachment's filename. The issue impacts desktop em

CVE advisoryCRITICAL

CVE-2026-84372

Predis PHP Client CRLF Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Predis PHP client allows specially crafted pipeline commands to be interpreted as additional commands, potentially enabling attackers to modify, delete, or disrupt data on Redis servers. This occurs due to improper parsing of serialized data on cluster or replication connections.

CVE advisoryKnown Exploit

CVE-2026-83549

SonicWall SMA1000 OS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A post-authentication OS command injection vulnerability exists in the SMA1000 Appliance Management Console. This could allow an authenticated administrator to execute arbitrary OS commands, potentially leading to remote code execution. This issue is classified as internal, but its relevance depends on the exposure and

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-83548

SMA1000 Appliance Work Place Pre-authentication SSRF Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the SMA1000 Appliance Work Place interface, allowing unauthenticated remote attackers to access sensitive functions and perform unauthorized operations via an unintended path. This could impact system integrity and potentially expose service behavior.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-54391

Proxmox VE Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Proxmox VE versions prior to 8.0.4 have an authentication bypass vulnerability in the API login endpoint that allows unauthenticated attackers to impersonate any enabled user by providing an arbitrary value for the `tfa-challenge` parameter. This could grant unauthorized access to the virtualization environment and its

CVE advisoryCRITICAL

CVE-2026-73749

AOS-CX Daemon Improper Input Processing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a daemon of AOS-CX that allows improper processing of malformed input, potentially enabling remote code execution with elevated privileges. An unauthenticated remote attacker could exploit this by sending specially crafted packets to the affected service, making it crucial to determine if your

CVE advisoryCRITICAL

CVE-2026-76658

HPE Fabric Composer SSH Daemon Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in HPE Networking Fabric Composer's SSH daemon, enabling unauthenticated remote attackers to execute arbitrary commands with administrative privileges. This could lead to complete system compromise on vulnerable hosts if the SSH daemon is reachable. You should care because this affects c

CVE advisoryCRITICAL

CVE-2026-76657

HPE Networking Fabric Composer Authentication Bypass Leading to Full Host Compromise.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in HPE Networking Fabric Composer's API, allowing unauthenticated remote attackers to bypass security controls and gain administrative privileges, potentially leading to a full host compromise. This issue is relevant because network management systems are high-value targets and could exp

CVE advisoryCRITICAL

CVE-2026-73701

HPE Networking Fabric Composer Unauthenticated Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in HPE Networking Fabric Composer's underlying operating system that could allow an unauthenticated remote attacker to execute arbitrary code with privileged access, leading to a complete host compromise. This could occur if specific, externally controlled preconditions are met, making i

CVE advisoryCRITICAL

CVE-2026-73700

HPE Networking Fabric Composer Stored XSS Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in HPE Networking Fabric Composer's web interface allows an authenticated low-privilege user to perform a stored cross-site scripting attack against an administrator. This could enable arbitrary script execution in an administrator's browser, potentially impacting the interface's integrity.

CVE advisoryCRITICAL

CVE-2026-52111

Fast-note-sync-service Privilege Escalation via Admin Configuration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A synchronization service has a critical flaw allowing unauthenticated attackers to escalate privileges by reaching an admin configuration endpoint. This could expose authentication keys and grant unauthorized administrative control. The primary concern is determining if this technology is in use.

CVE advisoryCRITICAL

CVE-2026-19593

OpenAI Codex Desktop Arbitrary Code Execution via Git Metadata

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in OpenAI Codex Desktop allows an attacker to execute arbitrary programs with user privileges by tricking a user into opening a specially crafted Git repository. This could lead to unauthorized access to files and credentials if the user opens such a repository. The vulnerability requires local interact

CVE advisoryCRITICAL

CVE-2026-51934

Tenda A18 Buffer Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability exists in Tenda A18 devices, allowing remote attackers to execute arbitrary code. This flaw could impact network device operations and security if exploited. The primary concern is identifying affected devices and understanding their exposure.

CVE advisoryCRITICAL

CVE-2026-79687

Dell PowerStore SDNAS Missing Authentication Filesystem Access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Dell PowerStore SDNAS has a critical vulnerability allowing unauthenticated remote attackers filesystem access. The platform's critical functions lack proper authentication. This could lead to unauthorized access to stored data if the system is reachable.

CVE advisoryCRITICAL

CVE-2026-51770

TOTOLINK T6 QoS Configuration Forwarding Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated network vulnerability in TOTOLINK devices allows attackers to forward custom Quality of Service settings to the master configuration by sending a crafted MQTT message. This could potentially disrupt network traffic or redirect it in unintended ways. It is important to determine if affected TOTOLINK d

CVE advisoryCRITICAL

CVE-2026-51769

TOTOLINK T6 Unauthenticated Restart Cloud Update via MQTT

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An improper access control vulnerability in a TOTOLINK router function allows unauthenticated attackers to restart cloud update checks by sending a crafted MQTT message. This could potentially impact device integrity and availability. It is recommended to confirm the relevance and exposure for affected consumer devices

CVE advisoryCRITICAL

CVE-2026-51767

TOTOLINK T6 MQTT Pairing Reset and Reboot Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated attacker can exploit a flaw in the MQTT component of certain TOTOLINK routers to reset the device's pairing state and reboot it by sending a crafted message. This vulnerability could lead to service disruption. The presence and network exposure of these devices within the environment are currently un

CVE advisoryCRITICAL

CVE-2026-18931

Talassoft Industrial Management Software Hard-coded Credentials Allow Data Retrieval

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Talassoft Industrial Management Software allows for the retrieval of embedded sensitive data. If the software is network-reachable, unauthorized parties could exploit hard-coded credentials to access critical business information. You should care because this could lead to the exposure of confidentia

CVE advisoryCRITICAL

CVE-2026-78012

NetStaX EtherNet/IP Stack Silent Buffer Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the NetStaX EtherNet/IP Stack where a large, malformed network request can cause memory corruption or a device crash without error. This could enable remote attacks. The relevance of this issue depends on whether the affected technology is in use.

CVE advisoryCRITICAL

CVE-2026-9621

RSLinx Classic Malformed Packet Denial-of-Service Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A denial-of-service vulnerability exists in RSLinx Classic due to improper handling of malformed packets. A specially crafted packet can crash the service, disrupting industrial communication operations until restarted. This issue is relevant if RSLinx Classic is in use and accessible within your environment.

CVE advisoryCRITICAL

CVE-2026-51765

TOTOLINK T6 Mesh Record Manipulation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An incorrect access control vulnerability in the recvIndirectMeshInfo function allows unauthenticated attackers to insert or replace mesh neighbor records by sending a crafted MQTT message to the cs_broker component, potentially disrupting network operations.

CVE advisoryCRITICAL

CVE-2026-51763

TOTOLINK T6 MQTT Unauthenticated Client Disconnection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated flaw in a TOTOLINK router's `freeStaClient` function allows attackers to forcibly disconnect wireless clients by sending a crafted MQTT message. This vulnerability could disrupt network service availability for connected users. The issue is reachable externally, making it relevant for devices exposed

CVE advisoryCRITICAL

CVE-2026-51762

TOTOLINK T6 Mesh Information Control Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated remote attacker can exploit a vulnerability in TOTOLINK routers affecting mesh information control. Attackers can send a crafted MQTT message to disrupt the router's mesh state, potentially impacting its functionality. Confirming the presence and exposure of this technology in your environment is adv

CVE advisoryCRITICAL

CVE-2026-51754

TOTOLINK T6 MQTT Unauthenticated Slave IP Overwrite

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can overwrite a router's slave IP inventory by sending a crafted MQTT message, potentially allowing unauthorized control over the device and its network. This vulnerability, affecting a common internet-facing gateway device, could impact the integrity of the network configuration.

CVE advisoryCRITICAL

CVE-2026-51750

TOTOLINK T6 Mesh Channel Vulnerability Allows Unauthenticated Control

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An access control vulnerability in TOTOLINK mesh routers allows unauthenticated attackers to rescan and change the primary mesh channel by sending a crafted MQTT message. This could disrupt mesh network operations. It is uncertain if these devices are exposed externally.

CVE advisoryCRITICAL

CVE-2026-18808

Klemsan KIO Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability exists in Klemsan Internet Objects (KIO), potentially allowing unauthorized arbitrary code execution. This critical issue, reachable via a network, could lead to system compromise. Confirming the use of KIO and assessing its network exposure is crucial for understanding potential risks to

CVE advisoryCRITICAL

CVE-2026-18210

TRtek Store SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in TRtek's Store application, potentially allowing attackers to manipulate database queries. If reachable, this could lead to unauthorized access or modification of sensitive data. Determining the presence and exposure of this technology is crucial.

CVE advisoryCRITICAL

CVE-2026-84149

ERP System Source Code Exposure via Public .git Directory

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in an ERP system exposes repository information via a publicly accessible .git directory. An unauthenticated remote attacker could exploit this by accessing the directory to retrieve metadata and files, potentially reconstructing the application's source code. This could lead to the exposure of

CVE advisoryCRITICAL

CVE-2026-84148

ERP System API Authentication Authorization Bypass Leads to Sensitive Data Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in an ERP system's API endpoint allows unauthenticated remote attackers to access sensitive user information by manipulating parameters, bypassing authentication and authorization controls. This could lead to the exposure of other users' data.

CVE advisoryCRITICAL

CVE-2026-84141

Graphics ImageLib Integer Overflow in Mozilla Firefox and Thunderbird

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the graphics image processing component of Firefox and Thunderbird. An integer overflow could allow an attacker to execute remote code by processing a crafted image, potentially impacting data and system availability. It is important to determine if affected software is in use.

CVE advisoryCRITICAL

CVE-2026-84140

Firefox and Thunderbird DOM Navigation Site Isolation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A site isolation vulnerability exists in the DOM: Navigation component of Firefox and Thunderbird, potentially allowing attackers to compromise data confidentiality, integrity, and availability if triggered. The relevance and reachability of this issue should be confirmed.

CVE advisoryCRITICAL

CVE-2026-84134

Mozilla Firefox and Thunderbird Profile Backup Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Profile Backup component of Mozilla Firefox and Thunderbird that could allow unauthorized access to sensitive user data if reachable. The exact impact and exposure within your environment require further confirmation.

CVE advisoryCRITICAL

CVE-2026-84133

Mozilla Firefox and Thunderbird Site Isolation DOM Push Subscriptions Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical site isolation vulnerability exists in the DOM: Push Subscriptions component of Mozilla Firefox and Thunderbird. This issue could allow an attacker to access sensitive information or affect service behavior if a user interacts with malicious content. The relevance and exposure to your environment need to be

CVE advisoryCRITICAL

CVE-2026-84129

Firefox and Thunderbird Site Isolation DOM Navigation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A site isolation flaw in the DOM: Navigation component of Firefox and Thunderbird could allow remote attackers to compromise data. While fixed in recent versions, it's important to confirm if your environment uses affected software to understand potential exposure and impact on user data.

CVE advisoryCRITICAL

CVE-2026-84121

Firefox DOM Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw exists in the browser's DOM security component, allowing a sandbox escape if reachable. Exploitation requires users to visit malicious content, potentially leading to system compromise. Verifying user exposure and business criticality is essential.

CVE advisoryCRITICAL

CVE-2026-84119

Firefox DOM Navigation Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Firefox's DOM Navigation component allows for a sandbox escape. If reachable, this could impact confidentiality, integrity, and availability. It is important to determine the relevance and exposure of this vulnerability within our environment.

CVE advisoryCRITICAL

CVE-2026-51747

TOTOLINK T6 Indirect Mesh Heartbeat Disclosure Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An incorrect access control vulnerability exists in TOTOLINK networking equipment that allows unauthenticated attackers to emit indirect mesh heartbeat information via a crafted MQTT message. This could expose internal network signals and affect router communication. Readers should confirm relevance and understand pote

CVE advisoryCRITICAL

CVE-2026-51744

TOTOLINK T6 Mesh Configuration Synchronization Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit a mesh configuration synchronization vulnerability in TOTOLINK devices by sending a crafted MQTT message. This could allow them to force configuration synchronization from an attacker-controlled host, potentially impacting network behavior and configuration.

CVE advisoryCRITICAL

CVE-2026-51743

TOTOLINK T6 Guest Wi-Fi Interface Disable Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An incorrect access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to disable guest Wi-Fi interfaces via a crafted MQTT message, potentially disrupting network services. Confirmation is needed to determine if this technology is in use and poses a relevant exposure.

CVE advisoryCRITICAL

CVE-2026-18765

Teracity E-OSB SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in Teracity E-OSB could allow unauthorized access to or modification of sensitive data if reachable. This threat impacts systems that process data through E-OSB, requiring an assessment of its presence and exposure within the environment.

CVE advisoryCRITICAL

CVE-2026-84189

LibreNMS Oxidized Integration Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

LibreNMS contains a stored cross-site scripting vulnerability in its Oxidized integration, where crafted JSON data from an attacker-controlled URL can execute malicious scripts within the device configuration page, impacting all users who view it. This requires administrator configuration of the integration to a malici

CVE advisoryCRITICAL

CVE-2026-18550

Nokri WordPress Theme Account Takeover Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the Nokri WordPress theme, allowing unauthenticated attackers to take over any user account, including administrators, via an insecure password reset function. This could lead to complete website compromise and data control.

CVE advisoryCRITICAL

CVE-2023-54356

Kyverno Weak TLS Cipher Suite Vulnerability Affects Long-Lived Connections

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Kyverno's TLS endpoints, when configured with specific older cipher suites, are vulnerable to the Sweet32 attack, potentially allowing an attacker to recover small amounts of plaintext over long, high-traffic connections. This issue is fixed in updated versions.

CVE advisoryCRITICAL

CVE-2026-4813

Lutece Core XSL Export RCE via Malicious Stylesheets

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Lutece Core's XSL export management allows authenticated administrators to remotely execute code by uploading a malicious XSL stylesheet. This can occur if the system's XML/XSLT processing is not secured, leading to arbitrary code execution on the server during user export operations. This i

CVE advisoryCRITICAL

CVE-2026-78319

TOCTOU Race Condition Allows Unauthorized Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A service in affected products has a Time-of-Check Time-of-Use race condition that an unauthenticated remote attacker could exploit to bypass security controls, potentially resulting in unauthorized code execution. The specific products and services affected are not detailed, so their relevance to your environment is u

CVE advisoryCRITICAL

CVE-2026-75865

WPLP Cookie Consent WordPress Plugin Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in a WordPress plugin that handles cookie consent, allowing unauthenticated attackers to upload arbitrary files to the server. This could lead to remote code execution, compromising server security. Confirm if this plugin is in use and assess its exposure.