NVD disclosure day

Published threat advisories for September 3, 2026

CVE advisoryCRITICAL

CVE-2026-85440

MOOS core-moos Heap Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A pre-authentication heap overflow vulnerability exists in MOOS core-moos packet handling, allowing remote attackers to write arbitrary data by declaring a negative packet length before authentication. This could impact system integrity and availability if the technology is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-85437

MOOS-IvP Buffer Overflow in String Decoders

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

MOOS-IvP software has multiple buffer overflow vulnerabilities in its string decoders that can be exploited by crafting malicious encoded strings. If reachable, an attacker could potentially execute arbitrary code on affected systems through MOOS variables or log files. The relevance of this specialized marine robotics

CVE advisoryCRITICAL

CVE-2026-85435

MOOS-IvP uFldNodeBroker Unauthenticated Shore Route Enrollment.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in MOOS-IvP's uFldNodeBroker allows unauthorized enrollment of shore routes, potentially exposing vehicle traffic including sensor and control data. While the technology is specialized for autonomous vehicles and not typically internet-facing, any use of this component requires verification of its relev

CVE advisoryCRITICAL

CVE-2026-85434

MOOS-IvP uFldShoreBroker Bridge Route Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in MOOS-IvP's uFldShoreBroker allows unauthenticated attackers to redirect bridged variables by sending forged ping messages. This could lead to the manipulation of communication routes and potentially compromise control signals within specialized autonomous systems.

CVE advisoryCRITICAL

CVE-2026-85433

MOOS essential-moos pShare Route Reconfiguration Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The MOOS essential-moos pShare component has a vulnerability allowing unauthorized reconfiguration of network routes and listeners at runtime. An attacker could exploit this by sending crafted messages, potentially redirecting or duplicating bus traffic to attacker-controlled destinations, which could impact system ope

CVE advisoryCRITICAL

CVE-2026-85428

MOOSDB HTTP Server Authentication Bypass Allows Unauthenticated Variable Writes

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication bypass vulnerability in the optional MOOSDB HTTP server allows unauthenticated clients to write variables, potentially modifying actuator and override commands. This issue requires the affected technology to be reachable, and its relevance depends on its use within our operations. The uncertainty lies

CVE advisoryCRITICAL

CVE-2026-85427

MOOS essential-moos pAntler Remote Code Execution via Unauthenticated Mission File.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in MOOS essential-moos's pAntler component, allowing unauthenticated attackers to execute arbitrary code. By publishing a crafted `MISSION_FILE` message to the MOOSDB, an attacker can bypass authentication and cause `pAntler` to run malicious commands. This could lead to unauthorized pro

CVE advisoryCRITICAL

CVE-2026-85426

MOOS-IvP uMemWatch Command Injection via Client Names

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The MOOS-IvP uMemWatch component is vulnerable to command injection due to insufficient sanitization of MOOS client names. Attackers can exploit this by embedding shell metacharacters into client names, leading to the execution of arbitrary commands with the privileges of the uMemWatch process. This vulnerability is re

CVE advisoryCRITICAL

CVE-2026-85425

MOOS-IvP iSay Command Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

MOOS-IvP iSay contains a critical remote code execution vulnerability where unsanitized input in the SAY_MOOS variable handler can be used to execute arbitrary shell commands. This means an attacker could potentially run unauthorized commands on affected systems.

CVE advisoryCRITICAL

CVE-2026-85424

MOOS Core Missing Authentication in Wire Protocol Allows Database Clear

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The MOOS core middleware has a vulnerability allowing unauthenticated network clients to connect and execute privileged operations. This could enable attackers to reset all database variables and clear message queues, potentially impacting data integrity and operational continuity. Confirmation of its use within our en

CVE advisoryCRITICAL

CVE-2026-83711

Azure AD B2C Authorization Bypass Leads to Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authorization bypass in Microsoft Azure Active Directory B2C allows an attacker to elevate privileges over a network. This could lead to unauthorized access and privilege escalation within the identity management service, impacting user authentication and authorization for web and mobile applications.

CVE advisoryCRITICAL

CVE-2026-80098

Copilot Studio Privilege Escalation via Signature Verification Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper cryptographic signature verification in Copilot Studio could allow an unauthorized attacker to elevate privileges over a network. This vulnerability is reachable via the network and, if exploited, could impact system integrity and allow unauthorized access. It is important to determine if Copilot Studio is

CVE advisoryCRITICAL

CVE-2026-70352

Azure AI Language Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Azure AI Language services due to missing authentication for a critical function, potentially allowing unauthorized network access to elevate privileges. This could impact the confidentiality, integrity, and availability of the service.

CVE advisoryCRITICAL

CVE-2026-62916

Microsoft Entra ID Authentication Bypass Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in Microsoft Entra ID could allow unauthorized attackers to elevate privileges over a network. This impacts a cloud-based identity and access management service, a globally reachable, internet-facing identity provider. Understanding the relevance and exposure of this issue is cruc

CVE advisoryCRITICAL

CVE-2026-85061

MapLibre GL JS Attribute Sanitization Bypass Executes Malicious Scripts.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in MapLibre GL JS allows attackers to execute malicious scripts in users' browsers by crafting specific attribution strings. This could lead to compromised user sessions. Confirming the use of this library and assessing exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-85050

Chrome for Android WebGL Out of Bounds Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical out-of-bounds write vulnerability in Google Chrome's Android WebGL component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This poses a risk due to the widespread use of browsers for accessing information and services.

CVE advisoryCRITICAL

CVE-2026-85047

Google Chrome iOS Transactions Platform Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in Google Chrome on iOS's Transactions Platform allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. This input validation vulnerability, rated as medium severity, could impact user data and service behavior if a user visits a malicious site.

CVE advisoryKnown Exploit

CVE-2026-85046

Chrome V8 Type Confusion Allows Sandbox Escapse

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A type confusion vulnerability in V8, a component of Google Chrome, permits remote attackers to execute arbitrary code via a crafted HTML page. This could enable unauthorized actions within a user's browser environment, impacting the behavior of web pages. The primary concern is to ascertain if this technology is deplo

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-85043

Chrome Network Vulnerability Allows Access Restrictions Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's network component could allow remote attackers to bypass system access restrictions by sending crafted network traffic. This issue is relevant because web browsers process untrusted content and are a common target for attackers. The potential impact on system access makes this a conce

CVE advisoryCRITICAL

CVE-2026-85394

python-jose Improper Key Validation Allows Token Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the python-jose library allows attackers to forge security tokens by improperly validating asymmetric keys in HMAC initialization. This means improperly formatted public keys could be accepted, leading to the creation of falsified tokens that pass verification, potentially impacting authentication an

CVE advisoryCRITICAL

CVE-2026-85391

Peppermint JWT Signing Secret Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hardcoded JWT signing secret in Peppermint allows unauthenticated attackers to forge session tokens, potentially granting them access to protected system data and service endpoints. This exposure is possible when the affected application is deployed in a way that exposes the JWT signing mechanism. System data and use

CVE advisoryCRITICAL

CVE-2026-82526

R2R Stacked SQL Injection via Vector Index Creation Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stacked SQL injection vulnerability in R2R's vector index creation endpoint allows unauthenticated attackers to execute arbitrary SQL commands by manipulating the index name. This could lead to unauthorized database access or modification if the index creation endpoint is reachable.

CVE advisoryCRITICAL

CVE-2026-58400

GeoNetwork Command Execution via XSLT Processing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

GeoNetwork's XSLT processor allows authenticated users to upload malicious stylesheets, enabling arbitrary command execution as the GeoNetwork process user. This vulnerability could impact systems managing spatially referenced resources, making it important to confirm if GeoNetwork is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-84834

JobSearch Unauthenticated PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a PHP-based job search component allows unauthenticated attackers to inject malicious code, potentially leading to complete system compromise. This issue affects software versions up to 3.2.0. The primary concern is confirming relevance and exposure due to the potential for severe impact.

CVE advisoryCRITICAL

CVE-2026-84814

Bricksforge Subscriber Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Bricksforge, a WordPress plugin, that could allow unauthenticated attackers to gain elevated privileges. This could lead to unauthorized control over the affected system and potential access to sensitive information. Organizations should confirm if Bricksforge is in use and assess pot

CVE advisoryCRITICAL

CVE-2026-84813

GeoDirectory Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a WordPress plugin, potentially allowing attackers to access or modify sensitive data without needing credentials. This issue is reachable via the network and poses a risk to data integrity and availability. Determining the plugin's usage and reachability is cruc

CVE advisoryCRITICAL

CVE-2026-84768

VikAppointments Booking Calendar SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the VikAppointments Services Booking Calendar, potentially allowing attackers to access or manipulate sensitive booking data. This issue is relevant due to the plugin's public-facing nature, which could expose it to exploitation over the network. Confirming its p

CVE advisoryCRITICAL

CVE-2026-84238

YITH Request a Quote for WooCommerce Premium Unauthenticated Broken Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical broken access control vulnerability exists in the YITH Request a Quote for WooCommerce Premium plugin. This flaw allows unauthenticated access, potentially leading to unauthorized data exposure or system compromise. Given the plugin's role in e-commerce, businesses using it should verify its presence and ass

CVE advisoryCRITICAL

CVE-2026-85216

MISP Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MISP has an authentication bypass vulnerability in its LDAP and LinOTP components due to insufficient credential validation. This could allow a remote, unauthenticated attacker to impersonate an existing user, potentially gaining access to sensitive threat intelligence data or performing privileged operations. Uncertai

CVE advisoryCRITICAL

CVE-2026-85183

Taipy WebSocket Cross-Site WebSocket Hijacking Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Taipy allows any web page to establish credentialed WebSocket connections to applications, potentially enabling attackers to invoke state variable modifications and action callbacks without authorization. This could lead to unauthorized control over application data and operations, making it importan

CVE advisoryCRITICAL

CVE-2026-85181

CAT Session Cookie Forgery via Unkeyed Hashcode Checksum.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in CAT allows attackers to forge session cookies by exploiting an unkeyed hashcode checksum and manipulating the `x-forwarded-for` header. This can lead to attackers bypassing authentication and gaining administrative access, potentially resulting in unauthorized control over system configurations.

CVE advisoryCRITICAL

CVE-2026-82180

Eclipse Arrowhead MQTT Certificate Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Eclipse Arrowhead's MQTT API allows an attacker to bypass authentication by submitting a forged X.509 certificate, granting them full system operator management access. This issue arises because the system fails to verify the signature or issuer of client-provided certificates. Deployments using the

CVE advisoryCRITICAL

CVE-2026-85154

WWBN AVideo Authentication Failure Allows Full Administrator Session Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WWBN AVideo has an authentication failure vulnerability allowing unauthorized users to gain full administrator access to video owner accounts. An attacker can exploit this by obtaining a non-expiring `video_id_hash` token, which grants indefinite administrator session access that bypasses password changes. This allows

CVE advisoryCRITICAL

CVE-2026-78080

Joomla Extension JooDatabase Lite Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in a Joomla extension, allowing unauthenticated attackers to inject malicious SQL code. This could lead to unauthorized access, modification, or deletion of sensitive data stored in the database. Confirm if your organization uses this extension to assess potential exposure

CVE advisoryCRITICAL

CVE-2026-78069

Joomla J2Store Missing Authorization Path Traversal and File Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a Joomla extension allows unauthenticated attackers to execute arbitrary code. This occurs due to missing authorization checks, enabling path traversal and file execution. The issue could lead to system and user data compromise.

CVE advisoryCRITICAL

CVE-2026-76178

Stored XSS in OCSReports Notification Templates Leading to Admin Session Compromise.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stored Cross-Site Scripting vulnerability exists in the notification template functionality. An administrator can inject malicious HTML, which executes as JavaScript when other administrators view the template customization, potentially compromising their sessions.

CVE advisoryCRITICAL

CVE-2026-76174

Ocsreports Unrestricted File Upload Allows Arbitrary Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unrestricted file upload vulnerability allows an authenticated administrator to upload and execute arbitrary PHP code. This could occur if the application fails to properly validate uploaded CSV files, potentially impacting server operations. The issue requires administrator privileges and internal system exposure i