NVD disclosure day

Published threat advisories for September 4, 2026

CVE advisoryCRITICAL

CVE-2026-75925

IXON VPN Client CRLF Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Improper handling of CRLF sequences in the IXON VPN Client allows an unauthenticated attacker to execute commands with root or SYSTEM privileges. This vulnerability persists across restarts and is not visually apparent to users, posing a risk to affected systems.

CVE advisoryCRITICAL

CVE-2026-81939

SonicWall NSM On-Prem Zip Slip Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Zip Slip vulnerability in SonicWall Network Security Manager's file upload and archive processing could permit an attacker to extract files outside intended directories. This could potentially lead to the overwriting or compromise of critical system files, impacting the integrity and availability of the management se

CVE advisoryCRITICAL

CVE-2026-78328

SonicWall NSM On-Prem Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing authorization vulnerability in SonicWall Network Security Manager's On-Prem Management interface could allow a lower-privileged administrator to escalate privileges to SuperAdmin. This could enable unauthorized changes to network security settings.

CVE advisoryCRITICAL

CVE-2026-78327

SonicWall NSM OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS Command Injection vulnerability in SonicWall Network Security Manager's On-Prem Management interface allows an authenticated SuperAdmin to inject and execute arbitrary commands on the host system, potentially leading to remote code execution. This issue is relevant because management consoles for security applian

CVE advisoryCRITICAL

CVE-2026-9317

Nango Runner tRPC Server Missing Authentication Allows Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Nango's runner tRPC server has a missing authentication vulnerability allowing unauthenticated attackers to run arbitrary JavaScript code if they have network access to the runner port. This bypasses security measures, potentially leading to code execution within the runner process. It is uncertain if this backend comp

CVE advisoryCRITICAL

CVE-2026-75430

PowerJob Worker Unauthenticated Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

PowerJob Worker has an unauthenticated HTTP endpoint that allows remote attackers to execute arbitrary code. This vulnerability could impact the integrity and availability of systems running the software, making it important to verify if your organization uses this technology and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-31020

DocsGPT Server-Side Template Injection Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side template injection vulnerability exists in DocsGPT's custom prompt feature, allowing unauthenticated attackers to execute arbitrary code on the server. This could impact application availability and integrity, making it crucial to verify if deployed instances are relevant and exposed.

CVE advisoryCRITICAL

CVE-2026-75160

X-Serie Gateway Firmware Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in X-Serie Gateway Firmware permits remote privilege escalation via specific CGI endpoints, enabling unauthorized access. Because gateway devices often face the internet, this issue could be reachable, posing a risk to system security.

CVE advisoryCRITICAL

CVE-2026-44402

Voltronic Power SNMP Web Pro Unauthenticated Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated vulnerability in Voltronic Power SNMP Web Pro allows remote attackers to execute arbitrary commands as root. Attackers can upload a crafted archive to the firmware update endpoint, leading to a full system compromise. Confirm if this technology is deployed and accessible within your network.

CVE advisoryCRITICAL

CVE-2026-19274

IBM Instana Agent RBAC Permission Hijacking Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in IBM Instana Agent Operator could allow an authenticated user to hijack or destroy another tenant's cluster-level RBAC permissions by manipulating cluster-scoped RBAC objects due to a lack of namespace disambiguation. This could lead to the revocation of monitoring access.

CVE advisoryCRITICAL

CVE-2026-18658

IBM Operational Decision Manager SQL Injection Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Operational Decision Manager contains a SQL injection vulnerability that an unauthenticated attacker could exploit to execute arbitrary SQL statements and potentially achieve remote code execution by writing a web shell. This could impact business operations if the affected technology is in use and exposed.

CVE advisoryCRITICAL

CVE-2026-85696

SadTalker OS Command Injection via Audio Filename.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability exists in SadTalker's video muxing process, allowing attackers to execute arbitrary system commands by uploading audio files with crafted filenames. This could lead to unauthorized system control if the technology is reachable.

CVE advisoryCRITICAL

CVE-2026-85694

LaVague PythonFromMarkdownExtractor RCE via Untrusted Output

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A remote code execution vulnerability in LaVague allows attackers to execute arbitrary Python code by injecting malicious content through web pages. This occurs when the affected component evaluates untrusted language model output derived from web content. The primary concern is determining if this technology is releva

CVE advisoryCRITICAL

CVE-2026-85688

TEN Framework Arbitrary File Read Write via TMAN Designer API

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in TEN Framework's TMAN Designer API that allows unauthenticated attackers to read and write arbitrary files. This could lead to code execution by modifying system files. Confirmation of technology usage, network exposure, and business criticality is necessary to understand the potential impact.

CVE advisoryCRITICAL

CVE-2026-85672

Zerox OS Command Injection Via Malicious File Extensions

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability in zerox allows attackers to execute arbitrary commands by crafting malicious document URLs. This occurs because the file download mechanism unsafely interpolates temporary file extensions into shell commands. The potential for unauthorized command execution makes this a si

CVE advisoryCRITICAL

CVE-2026-85667

Unauthenticated Webhook Message Injection and SSRF in Xiaobei

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Xiaobei through version 5.5.2 lacks authentication on webhook endpoints, enabling unauthenticated attackers to inject arbitrary messages and exploit unvalidated media URL fetching for server-side request forgery against internal services. This vulnerability is reachable over the network without authentication.

CVE advisoryCRITICAL

CVE-2026-85661

Excel-mcp-server Arbitrary File Read Write via Stdio Mode

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in excel-mcp-server allows attackers to read and write arbitrary files when a specific path confinement is not enforced in stdio mode. If reachable, this could permit unauthorized access to any file accessible by the server process. Confirmation of the technology's usage and exposure is needed to determ

CVE advisoryCRITICAL

CVE-2026-85660

cli-mcp-server Command Allowlist Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A command allowlist bypass vulnerability exists in a command-line server when specific operator settings are enabled, allowing attackers to execute unintended commands by bypassing validation checks. This could impact system behavior and data if the vulnerable server is reachable and relevant to your environment.

CVE advisoryCRITICAL

CVE-2026-85625

Sift.js Prototype Pollution RCE via $where

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the sift.js JavaScript library allows for arbitrary code execution. This occurs when the library enumerates query keys, potentially including a malicious operator that compiles a string into executable code by default. If a prototype pollution primitive elsewhere in the process can set a specific ope

CVE advisoryCRITICAL

CVE-2026-85620

Postgres MCP Pro Restricted Mode Bypass Allows Arbitrary File Reading

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Postgres MCP Pro has a vulnerability allowing attackers to bypass security restrictions and read arbitrary files. This could lead to the exposure of sensitive data if the affected component is reachable. Organizations should confirm their instances and assess potential exposure to sensitive information.

CVE advisoryCRITICAL

CVE-2026-85614

OpenPanel Unauthenticated Server-Side Request Forgery in Site Checker

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability exists in OpenPanel, allowing unauthenticated attackers to make the server send requests to internal or cloud services. This could expose sensitive information from those destinations, such as headers and SSL certificate details.

CVE advisoryCRITICAL

CVE-2026-85602

Grav Form Plugin reCAPTCHA v3 Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the Grav Form plugin allows anonymous attackers to bypass reCAPTCHA v3 bot protection by manipulating the validation process. This means malicious actors could submit form data without proper verification, potentially enabling automated abuse of web forms. This issue is critical for public-facing for

CVE advisoryCRITICAL

CVE-2026-85595

Traefik DigestAuth Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Traefik's digestAuth middleware allows attackers to bypass authentication on protected routes by computing a valid digest response with an empty secret for unknown usernames. This could lead to unauthorized access to sensitive resources if Traefik is used for ingress or edge services.

CVE advisoryCRITICAL

CVE-2026-85184

@fastify/middie Access Control Bypass via Request Target Mismatch

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated network attacker can exploit a vulnerability in @fastify/middie to bypass path-based access controls, potentially reaching sensitive routes without authorization. This occurs because @fastify/middie and the Fastify router evaluate request targets differently, allowing attackers to circumvent security

CVE advisoryCRITICAL

CVE-2026-82923

AI Website Builder WordPress Plugin Unauthenticated Plugin and Content Management

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the AI Website Builder WordPress plugin, allowing unauthenticated attackers to gain full control of websites. Attackers can install plugins, import content, write files, and delete site data, potentially leading to remote code execution if the server is configured to execute PHP from

CVE advisoryCRITICAL

CVE-2026-85085

Canva Android WebView Vulnerability Allows Session Communication

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Canva Android App contains a vulnerability that permits an external web page to communicate with the app using a user's session. This could potentially lead to unauthorized actions or data exposure if a user accesses a malicious page. Uncertainty exists regarding the specific impact and reachability of this threat.

CVE advisoryCRITICAL

CVE-2026-69657

XING CPTrans-ME-X Default Password Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A default password vulnerability in XING CPTrans-ME-X allows unauthorized login if the credential is known. This could potentially expose device configuration and operational data. Confirm if this product is in use and assess its network exposure to understand the relevance of this threat.

CVE advisoryCRITICAL

CVE-2026-62928

XING CPTrans-ME-X OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

XING CPTrans-ME-X has a critical OS command injection vulnerability, allowing unauthenticated attackers to execute arbitrary commands remotely. This affects network communication devices and may lead to system compromise. Confirming its relevance and exposure is necessary.

CVE advisoryCRITICAL

CVE-2026-15354

ACPT WordPress Plugin Privilege Escalation Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The ACPT (Premium) WordPress plugin has a privilege escalation vulnerability that allows unauthenticated attackers to take over any user account, including administrators, by overwriting email addresses and passwords. This is possible if a public ACPT form allows anonymous submissions.

CVE advisoryCRITICAL

CVE-2026-85509

FreeIPMI Stack Buffer Overflow

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

FreeIPMI has a stack-based buffer overflow vulnerability that can occur when a Baseboard Management Controller returns more data than requested. This could potentially allow for unauthorized system control if the vulnerability is reachable. Further assessment is needed to determine if FreeIPMI is deployed and exposed i

CVE advisoryCRITICAL

CVE-2026-85508

FreeIPMI Stack Buffer Overflow Vulnerability CVE-2026-85508

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in FreeIPMI's `ipmi-oem` component, specifically within a function that handles Dell system IPv6 information. This flaw could allow an attacker to remotely execute code or cause a denial-of-service by exploiting a stack-based buffer overflow. The reader should care because this could lea

CVE advisoryCRITICAL

CVE-2026-85507

FreeIPMI cmc-info stack-based buffer overflow vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in FreeIPMI's `ipmi-oem` component due to a stack-based buffer overflow. If reachable, this could allow an unauthenticated attacker to execute arbitrary code, potentially leading to system compromise and data loss. It is uncertain if this issue is exposed externally in typical deployment

CVE advisoryCRITICAL

CVE-2026-85506

FreeIPMI Stack Buffer Overflow Vulnerability in Dell iDRAC Information Retrieval

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical stack-based buffer overflow vulnerability exists in FreeIPMI's `ipmi-oem` component when processing Dell iDRAC system information. This flaw could potentially allow for system compromise if reachable. Readers should care because this impacts the confidentiality, integrity, and availability of affected system

CVE advisoryCRITICAL

CVE-2026-85504

FreeIPMI Stack Buffer Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

FreeIPMI contains a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code by sending malformed responses. This issue arises from how the software handles specific management data and may be reachable over a network if the affected component is exposed.

CVE advisoryCRITICAL

CVE-2026-85148

Lightstar SmartIT Desktop Manager Hard-coded Credentials Remote Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Lightstar's SmartIT Desktop Manager, allowing unauthenticated remote attackers to exploit a hard-coded password. This could enable unauthorized remote access to user hosts. Confirmation of the technology's use and network exposure is essential to understand its relevance.

CVE advisoryCRITICAL

CVE-2026-85146

Lightstar SmartIT Desktop Manager Hard-coded Credentials Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Lightstar SmartIT Desktop Manager allows unauthenticated remote attackers to retrieve hard-coded SSH credentials from the application's source code. This could enable unauthorized access to the SmartIT Agent. The relevance and exposure of this vulnerability within your environment are uncertain.

CVE advisoryCRITICAL

CVE-2026-75754

ASUS Control Center Authentication Bypass and SSRF Vulnerability Enables Root Shell Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Critical vulnerabilities in ASUS Control Center allow unauthorized users to bypass authentication and exploit server-side request forgery and hard-coded credentials. This could enable an attacker to obtain an encryption key, enable SSH, and gain root shell access to read, write, or delete data, and remotely control all

CVE advisoryCRITICAL

CVE-2026-67402

ConfigServer Security & Firewall Remote Command Execution via Insecure Apache Configuration

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An insecure Apache configuration in a firewall and security management tool allows remote, unauthenticated attackers whose IP addresses are blocked to execute arbitrary commands. The vulnerability stems from how the tool maps system directories as executable programs, posing a risk to system integrity if exploited. Con