NVD disclosure day

Published threat advisories for September 2, 2026

CVE advisoryCRITICAL

CVE-2026-66786

Submariner Cert-Auth Configuration Injection Leading to Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in Submariner's cert-auth mode where unvalidated connection configurations can be exploited to inject arbitrary commands, potentially leading to remote code execution as root on gateway nodes. This occurs when a malicious cluster publishes a specially crafted CableName containing newline characte

CVE advisoryCRITICAL

CVE-2026-53671

PREVAIL eBPF Verifier Incorrectly Ignores Memory Writes

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in PREVAIL, an eBPF program verifier, where memory writes are improperly ignored, allowing crafted programs to bypass safety checks. This could result in unsafe eBPF programs being incorrectly flagged as secure, raising concerns about the integrity of verified programs. The issue is patched in ve

CVE advisoryCRITICAL

CVE-2026-53670

Prevail eBPF Verifier Offset Update Flaw

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the PREVAIL eBPF verifier allows crafted programs to bypass security checks, potentially corrupting memory during runtime. This issue is present in versions prior to 0.2.4. The reader should care because memory corruption can lead to unpredictable behavior in systems that process eBPF programs.

CVE advisoryCRITICAL

CVE-2026-53649

Joro Local API Unauthenticated Plugin Upload RCE

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Joro's default proxy mode exposes an unauthenticated local API that allows cross-origin JavaScript to upload plugins and trigger restarts, leading to remote code execution as the operator's user. This vulnerability is reachable via a malicious webpage visit if the framework is running.

CVE advisoryCRITICAL

CVE-2026-20274

Cisco IOS XR Software Improper Resource Control Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Cisco IOS XR Software has critical vulnerabilities related to improper resource control. If reachable, these flaws could allow an attacker to compromise the system, impacting network integrity and availability. It is important to confirm if affected technology is present and potentially exposed within your network.

CVE advisoryCRITICAL

CVE-2026-20212

Cisco Nexus 9000 Silicon One RCE via Exposed TCP Ports

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Cisco Nexus 9000 Series Switches allows remote, unauthenticated attackers to execute code with root privileges. Exploitation is possible if TCP ports 43210 or 43211 are reachable, which could lead to device reloads and network service disruption. This impacts critical network infrastructure.

CVE advisoryCRITICAL

CVE-2026-78689

NGINX JavaScript XML Module Namespace Prefix Parser Out-of-Bounds Write

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in NGINX JavaScript's XML module allows unauthenticated remote attackers to cause denial of service through out-of-bounds writes, potentially leading to worker crashes or memory growth, and possibly code execution. This impacts NGINX configurations processing XML data, especially during SAML signature v

CVE advisoryCRITICAL

CVE-2026-82955

Eclipse aeriOS API Gateway KrakenD JWKS Security Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An API Gateway component in a development version of Eclipse aeriOS contains a flaw where security for validating JSON Web Key Set (JWKS) information is disabled by default. This could allow an attacker to intercept communications and provide a malicious JWKS to compromise token validation. The vulnerability has been a

CVE advisoryCRITICAL

CVE-2026-4357

Embed HTML5 Game WordPress Plugin Unauthenticated PHP Backdoor Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin allows unauthenticated attackers to upload PHP backdoors, potentially leading to full website compromise and arbitrary code execution. This vulnerability is reachable via the network and affects websites using the affected plugin.

CVE advisoryCRITICAL

CVE-2025-9314

Developer Tools WordPress Plugin Unauthenticated File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Developer Tools WordPress plugin that allows unauthenticated arbitrary file uploads. This could enable an attacker to upload malicious files, potentially leading to system compromise. Confirming the use and exposure of this plugin is important.

CVE advisoryCRITICAL

CVE-2026-73475

Drupal Commerce PayPal Forceful Browsing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization flaw in Drupal Commerce PayPal could permit forceful browsing, potentially exposing sensitive payment and order data to unauthenticated attackers. This impacts e-commerce platforms using Drupal, necessitating verification of module usage and exposure.

CVE advisoryCRITICAL

CVE-2026-84795

Craft CMS Admin Flag Inheritance Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Craft CMS allows attackers to gain administrator privileges by registering with a deactivated admin's email if public registration and disabled email verification are enabled. This could lead to unauthorized access and impact system integrity and availability.

CVE advisoryCRITICAL

CVE-2026-81294

Authorizer Plugin Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the Authorizer technology. If reachable, an attacker could exploit this to gain unauthorized administrative control over a system. This could impact systems that rely on Authorizer for user access management.

CVE advisoryCRITICAL

CVE-2026-81286

Unauthenticated SQL Injection in WCFM Marketplace versions prior to 3.8.1

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WCFM Marketplace plugin. This flaw could allow attackers to inject malicious SQL, potentially leading to unauthorized access or modification of sensitive marketplace data. It is uncertain if this vulnerability is being actively exploited or what specific data

CVE advisoryCRITICAL

CVE-2026-78657

SigmaForms Pro File Deletion Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The SigmaForms Pro WordPress plugin has a vulnerability that allows unauthenticated attackers to delete arbitrary files on the server by exploiting insufficient file path validation in the submission file deletion function. This could lead to remote code execution if critical system files are targeted.

CVE advisoryCRITICAL

CVE-2026-9055

Amelia WordPress Plugin Privilege Escalation Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the Amelia WordPress plugin, allowing unauthenticated attackers to escalate privileges to administrator. This is achieved by manipulating the customer update endpoint to elevate a user's role and overwrite administrator credentials, potentially leading to a complete website compromise

CVE advisoryCRITICAL

CVE-2026-84699

Team Password Manager Authentication Bypass in Local Password Reset

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Team Password Manager has a flaw in its local account password reset flow, allowing unauthenticated attackers to reset passwords and gain unauthorized access to user accounts. This vulnerability is reachable over the network, posing a risk to the sensitive credentials managed by the application. Confirming the use and

CVE advisoryCRITICAL

CVE-2026-84695

BookStack Stored Cross-Site Scripting via Drawing Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

BookStack's drawing upload feature contains a stored cross-site scripting vulnerability that allows attackers with editor permissions to upload SVG files with embedded scripts. These scripts can execute in administrator browsers when accessed through the image gallery API, potentially impacting sensitive information. C

CVE advisoryCRITICAL

CVE-2026-84354

Google Chrome FileSystem Authorization Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Google Chrome has an authorization flaw in its FileSystem component that, if exploited, could allow remote attackers to execute arbitrary code outside the browser's sandbox. Exploitation requires a user to visit a malicious HTML page, indicating that user interaction is necessary for this threat to be realized. This vu

CVE advisoryCRITICAL

CVE-2026-84353

Chrome for Android Shared Tab Groups Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on Android allows a remote attacker, through social engineering, to execute arbitrary code outside the sandbox via a crafted HTML page. This critical issue impacts device integrity and confidentiality when the browser is used. Uncertainty remains regarding exploitation me

CVE advisoryCRITICAL

CVE-2026-84333

Google Chrome for Android Dawn Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome on Android could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact devices if users visit malicious websites, requiring confirmation of exposure and management of browser updates.

CVE advisoryCRITICAL

CVE-2026-84325

Google Chrome DataTransfer Input Validation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's DataTransfer component could allow remote attackers to bypass system access restrictions by leveraging social engineering and a co-installed application. This could lead to unauthorized access or modification of system data if a user is tricked into interacting with a malicious link.

CVE advisoryCRITICAL

CVE-2026-84324

Use After Free in Chrome Proxy Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's proxy allows a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. This could lead to code execution on the user's system. Confirmation is needed to determine if this client-side vulnerability affects the environment.