NVD disclosure day

Published threat advisories for September 7, 2026

CVE advisoryCRITICAL

CVE-2026-86543

Knowns Management API Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Knowns management API, in versions prior to 0.30.0, can be accessed without authentication on all network interfaces by default. This allows attackers to provision public tunnels and re-publish the API at a publicly accessible address, potentially leading to unauthorized access and control.

CVE advisoryKnown Exploit

CVE-2026-75650

Adobe Commerce Template Injection Arbitrary Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Adobe Commerce has an improper neutralization vulnerability allowing arbitrary code execution. This could enable an attacker to run unauthorized commands on the system. The issue has a broad scope and does not require user interaction, making it a significant risk for affected systems.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-86478

JetBrains YouTrack Helpdesk Improper Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper authentication vulnerability in JetBrains YouTrack Helpdesk could allow unauthenticated account takeover by submitting a self-asserted email address. This could affect user accounts and potentially sensitive data. Organizations should confirm if they use this technology and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-7861

Next4Biz CSM Untrusted Data Deserialization Allows Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical deserialization vulnerability in Next4Biz CSM allows code injection via untrusted data. If reachable, this could impact system confidentiality, integrity, and availability. Organizations using this software should assess their exposure and business criticality.

CVE advisoryCRITICAL

CVE-2026-80164

Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell Secure Connect Gateway has an improper certificate validation vulnerability. An unauthenticated remote attacker could exploit this to gain unauthorized access. This is a critical gateway for managing Dell infrastructure, so confirming its presence and exposure in your environment is important.

CVE advisoryCRITICAL

CVE-2026-80129

Dell Secure Connect Gateway Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Dell Secure Connect Gateway could allow unauthenticated attackers to execute code remotely. This issue enables unauthorized system control over the network, potentially impacting data and services. Confirming deployment of this Dell product is advised to assess risk.

CVE advisoryCRITICAL

CVE-2026-86426

LibreNMS Authentication Bypass via API Type Confusion

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

LibreNMS's REST API contains an authentication bypass vulnerability allowing unauthenticated access to protected endpoints by sending numeric values instead of string tokens. This exploits MySQL type coercion, potentially enabling attackers to access sensitive device credentials and administrative features, which could

CVE advisoryCRITICAL

CVE-2026-76578

FreeIPA Self-Managed OTP Token ACI Allows Unauthenticated Administrator Group Membership.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in FreeIPA's self-managed OTP token configuration allows unauthenticated attackers to gain administrator privileges. This could enable an attacker to create a Kerberos principal and add it to the administrators group, leading to administrative control over identity management services.

CVE advisoryCRITICAL

CVE-2026-6223

BiHayat App Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the BiHayat App allows for authentication bypass due to improper restriction of excessive authentication attempts. This could enable unauthorized access to the application's features and data. The vendor has not responded to inquiries regarding this issue.

CVE advisoryCRITICAL

CVE-2026-61410

Dell SCG Missing Authorization Allows Remote Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell Secure Connect Gateway has a critical missing authorization vulnerability allowing unauthenticated remote attackers to execute commands. This could compromise system integrity and confidentiality by enabling unauthorized remote code execution. Organizations should confirm if they use this product and assess their

CVE advisoryCRITICAL

CVE-2026-86296

D-Link DIR-822A Stack Overflow Vulnerability in udhcpcd

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in D-Link DIR-822A routers affecting the `udhcpcd` component, which could allow remote attackers to cause a stack-based buffer overflow. This issue has been publicly disclosed, increasing the potential for exploitation and could impact device functionality. It is important to confirm if this tech

CVE advisoryCRITICAL

CVE-2026-16876

NEC UNIVERGE IX-R/IX-V WebGUI Authentication Bypass Command Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in the WebGUI of Series UNIVERGE IX-R/IX-V allows unauthorized users to execute arbitrary commands by tampering with messages sent over the internet. This impacts network devices accessible online, potentially leading to unauthorized control.