NVD disclosure day

Published threat advisories for September 8, 2026

CVE advisoryCRITICAL

CVE-2026-53581

OPNsense NTP Configuration Path Traversal Leading to Root File Overwrite

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OPNsense platforms contain a path traversal vulnerability in the NTP configuration module that allows an authenticated attacker to overwrite arbitrary system files as root. Given OPNsense's common deployment as an internet-facing firewall, this vulnerability could lead to system compromise if the NTP configuration is r

CVE advisoryCRITICAL

CVE-2026-85982

Auth0 AD/LDAP Connector Stored XSS Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stored cross-site scripting vulnerability exists in the Auth0 AD/LDAP Connector due to improper HTML encoding. An authenticated user or a local user on the connector's host could insert script content into directory attributes or log files. This script may execute in an administrator's browser when they view specific

CVE advisoryCRITICAL

CVE-2026-86464

Eclipse aeriOS Identity Manager Insecure Defaults Allow Administrative Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Insecure default configurations and credentials in the development version of Eclipse aeriOS's Identity Manager could allow an attacker to gain administrative access to the system or its database. This could lead to unauthorized access, modification, or creation of sensitive identity data, including user credentials an

CVE advisoryCRITICAL

CVE-2026-84869

ScreenConnect Client Unauthorized File Transfer and Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the ScreenConnect client that may allow unauthorized file transfers and execution during an active remote session. ScreenConnect servers are not impacted. This could lead to compromise of the client system if reachable or relevant.

CVE advisoryCRITICAL

CVE-2026-84197

Eclipse Ditto Node.js Client WebSocket Transport Certificate Validation Disabled

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Eclipse Ditto Node.js client's WebSocket transport disables certificate validation, allowing an attacker who can intercept the connection to impersonate the server, read, modify, or inject messages. This impacts client communication security and could expose credentials. Confirming the use and re

CVE advisoryCRITICAL

CVE-2026-49883

Missing Permission Check Allows Sensitive Data Monitoring on Wearables

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A missing permission check in the device's permissions manager could allow sensitive state data to be monitored locally. This vulnerability may lead to local information disclosure without user interaction or special privileges, impacting the confidentiality of device information.

CVE advisoryCRITICAL

CVE-2026-48273

ColdFusion Eval Injection Vulnerability Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An "Eval Injection" vulnerability in ColdFusion allows a low-privileged attacker to execute arbitrary code remotely without user interaction. If reachable, this could lead to system compromise and impact data confidentiality, integrity, and availability. Organizations using ColdFusion should confirm its presence and ex

CVE advisoryCRITICAL

CVE-2026-28659

MicroXR Blobstore Missing Permission Check Allows Local Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A missing permission check in MicroXR Blobstore could allow unauthorized access to other applications' files, potentially leading to local privilege escalation without additional execution privileges, as user interaction is not required. This raises concerns about unauthorized file access and data integrity on affected

CVE advisoryCRITICAL

CVE-2026-19232

Adobe Experience Manager Incorrect Authorization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Experience Manager has an incorrect authorization vulnerability that could allow a low-privileged attacker to execute arbitrary code, potentially gaining elevated access or control over a user's session without interaction. This external threat is relevant because the platform is often internet-facing.

CVE advisoryCRITICAL

CVE-2026-76201

Adobe Commerce Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject malicious scripts into form fields. If reachable, these scripts can execute in a victim's browser, potentially granting the attacker elevated access or control over the victim's account or session. This is

CVE advisoryCRITICAL

CVE-2026-76200

Adobe Commerce Stored XSS Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Commerce is affected by a stored Cross-Site Scripting vulnerability allowing attackers to inject malicious scripts into form fields. This could lead to the execution of malicious JavaScript in a victim's browser, potentially granting unauthorized access or control over their account or session. Confirmation of af

CVE advisoryCRITICAL

CVE-2026-66302

Skype for Business Network Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Skype for Business allows unauthorized network code execution by manipulating file names or paths. This could lead to compromised systems, impacting confidentiality, integrity, and availability. Organizations should confirm if this technology is in use and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-49921

Heap Buffer Overflow Vulnerability Enables Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical memory safety flaw allows remote code execution without user interaction. If reachable, this heap buffer overflow could enable attackers to compromise systems by sending malformed data over the network, necessitating an understanding of affected technologies and their exposure.

CVE advisoryCRITICAL

CVE-2026-28606

Android Bluetooth Pairing Logic Flaw Allows Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic error in Android's Bluetooth pairing can allow attackers to escalate privileges remotely without user interaction, bypassing normal pairing procedures. While this vulnerability has critical severity, its practical reach is limited by Bluetooth's short-range nature. Consider if sensitive data is on devices and a

CVE advisoryKnown Exploit

CVE-2026-85880

Windows ALPC Local Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in Windows ALPC allows a local attacker with authorization to elevate privileges. This means an attacker already on a system could potentially gain greater control, which is relevant for maintaining system integrity. Uncertainty exists regarding specific product versions and the potential b

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-83941

Entra ID Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Microsoft Entra ID, a cloud-based identity and access management service, due to missing authorization checks. If reachable, an authenticated attacker with network access could escalate privileges. This is significant because Entra ID is fundamental to managing user access and securit

CVE advisoryKnown Exploit

CVE-2026-81963

Windows Update Stack Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Update Stack involves improper link resolution, allowing a local attacker to elevate privileges. If reachable, this could grant unauthorized higher control over a system. This matters because it affects a core component and could lead to significant access gain.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-81376

Visual Studio Code Incomplete Comparison Security Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Visual Studio Code allows an unauthorized attacker to bypass security features over a network. This could impact confidentiality, integrity, and availability if a user interacts with malicious content or a compromised source. Confirming relevance and exposure is important for understanding developer

CVE advisoryCRITICAL

CVE-2026-78510

Microsoft Office Word Network Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical heap-based buffer overflow vulnerability exists in Microsoft Office Word that could permit an unauthorized attacker to execute code over a network. If reachable, this could potentially lead to broad system compromise. Understanding the relevance and exposure of this threat to our environment is key.

CVE advisoryCRITICAL

CVE-2026-78509

Microsoft Outlook Heap Overflow Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow in Microsoft Office Outlook could permit an unauthorized attacker to execute code over a network. This vulnerability, if reachable, may affect system confidentiality, integrity, and availability. The widespread use of Outlook makes its potential relevance to the environment a concern.

CVE advisoryCRITICAL

CVE-2026-78445

Windows Services for NFS Use After Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical use-after-free vulnerability in Windows Services for NFS allows network-based code execution by an unauthorized attacker. This could impact system integrity and availability if the service is exposed. Uncertainty remains regarding its actual deployment and reachability within the environment.

CVE advisoryCRITICAL

CVE-2026-77493

Microsoft Graphics Component Double Free Network Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. This could lead to a complete system compromise if the component is reachable. Leadership should confirm its relevance to the organization.

CVE advisoryCRITICAL

CVE-2026-73025

Windows iSCSI Weak Authentication Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Windows iSCSI, a network storage technology, allowing remote attackers to bypass security features due to weak authentication. If reachable, this could lead to unauthorized access and modification of sensitive storage data. Organizations should confirm if they use Windows iSCSI and as

CVE advisoryCRITICAL

CVE-2026-73010

Windows Failover Cluster Use After Free Network Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in Windows Failover Cluster allows an unauthorized attacker to execute code over a network, potentially impacting system availability and integrity. Confirmation of this technology's use and network exposure within the environment is crucial.

CVE advisoryCRITICAL

CVE-2026-73009

Windows SSTP Use After Free Allows Network Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A use-after-free vulnerability exists in Windows Secure Socket Tunneling Protocol, allowing an unauthorized attacker to execute code over a network. This could impact system integrity and confidentiality. The concern is to determine if the environment is affected, as it is exploitable over a network and allows unauthor

CVE advisoryCRITICAL

CVE-2026-72983

Windows ICS Use After Free Network Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free flaw in Windows Internet Connection Sharing (ICS) enables an unauthorized attacker to execute code remotely over a network by sending specially crafted network traffic. The specific reachability and impact are currently under analysis, and it is uncertain if this technology is in use within the environ

CVE advisoryCRITICAL

CVE-2026-72982

Windows Netlogon Stack Buffer Overflow Allows Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in the Windows Netlogon service, enabling unauthorized remote code execution over a network. This flaw could allow attackers to compromise affected systems by sending specially crafted network traffic. While Netlogon is typically protected and not exposed externally, the potential for sy

CVE advisoryCRITICAL

CVE-2026-72979

Windows DHCP Server Use After Free Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in Windows DHCP Server allows an unauthorized remote attacker to execute code over a network, impacting system integrity and service availability. This critical flaw requires assessment to confirm its relevance and potential exposure within our environment. The main concern is understandi

CVE advisoryCRITICAL

CVE-2026-70296

Windows Imaging Component Out-of-Bounds Write Allows Network Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An out-of-bounds write in the Windows Imaging Component could allow an unauthorized attacker to execute code over a network. This vulnerability might affect systems processing image files, potentially leading to unauthorized code execution. The relevance and exposure of this component within our environment need to be

CVE advisoryCRITICAL

CVE-2026-69910

Windows Hyper-V Network Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A stack-based buffer overflow in Windows Hyper-V permits an unauthorized attacker to execute code over a network. This vulnerability, if reachable, could impact the integrity and availability of affected systems. Readers should care because Hyper-V is core to modern infrastructure, and network-based code execution can

CVE advisoryCRITICAL

CVE-2026-69854

Spring Cloud Azure Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authentication vulnerability in Spring Cloud Azure could allow an unauthorized attacker to elevate privileges over a network. This matters because the technology is commonly used in cloud-native applications, potentially exposing network-accessible systems. The concern is confirming relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-69845

Windows DHCP Server Heap Overflow Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. This could impact the availability and integrity of affected systems, which are core network services responsible for IP address allocation. It is uncertain if exploitation is likely as DHCP servers are t

CVE advisoryCRITICAL

CVE-2026-69829

Windows Shell Heap Buffer Overflow Allows Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow in Windows Shell could allow an unauthorized attacker to execute code over a network. This critical vulnerability affects a core operating system component and may pose a risk to system integrity and confidentiality if reachable.

CVE advisoryCRITICAL

CVE-2026-69824

Microsoft Standard XPS Network Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical integer underflow vulnerability exists in Microsoft Standard XPS, potentially allowing an unauthorized attacker to execute code over a network. While typically a client-side component, its network-reachable nature means this flaw could enable remote code execution if exposed. Understanding and confirming the

CVE advisoryCRITICAL

CVE-2026-69819

RPC Runtime Out-of-Bounds Write Allows Network Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An out-of-bounds write vulnerability exists in the RPC Runtime, enabling unauthorized network-based code execution. If reachable, this could allow an attacker to compromise affected systems remotely. This issue is relevant for understanding potential impacts on core services and network-exposed components.

CVE advisoryCRITICAL

CVE-2026-69769

Windows HTTP Print Provider Heap Overflow Leads to Network Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow in the Windows HTTP Print Provider may permit an unauthorized attacker to execute code remotely. This could compromise system integrity and confidentiality if the vulnerable component is exposed. Readers should verify if this print service technology is in use and potentially reachable.

CVE advisoryCRITICAL

CVE-2026-69768

Windows RNDIS Heap Overflow Allows Network Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical heap-based buffer overflow vulnerability exists in Windows RNDIS, a network protocol. An unauthenticated attacker could exploit this remotely to execute code, potentially leading to system compromise. Leaders should understand the relevance and potential exposure of this protocol in their environment.

CVE advisoryCRITICAL

CVE-2026-69715

Windows DirectShow Out-of-Bounds Read Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds read in Windows Direct Show, a multimedia framework, may allow an unauthorized attacker to execute code over a network. The practical impact of this vulnerability is considered very unlikely in typical deployments due to Direct Show's primary use in local media processing. The key concern is to confirm

CVE advisoryHIGH

CVE-2026-69669

Windows Kernel Heap Overflow Vulnerability Allows Network Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in the Windows Kernel allows an unauthorized attacker to execute code over a network, potentially impacting system integrity and availability. The relevance and exposure of this vulnerability within our environment need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-69595

Windows Services for NFS ONCRPC XDR Driver Use After Free Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical use-after-free vulnerability in Windows Services for NFS allows unauthorized network access to execute code. This could impact system integrity and availability if the service is exposed. Confirming its use and network reachability is key to understanding potential risk.

CVE advisoryCRITICAL

CVE-2026-69590

Windows RRAS Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Windows Routing and Remote Access Service allows unauthenticated network attackers to execute arbitrary code on a victim machine, potentially leading to unauthorized access and system compromise. Because this service is often internet-facing for remote access, its exposure makes it a target.

CVE advisoryCRITICAL

CVE-2026-69586

Windows PDF Integer Overflow Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An integer overflow in Microsoft Windows PDF processing enables network-based code execution by an unauthorized attacker. The technology is Microsoft Windows PDF, and the vulnerability allows for remote code execution. It is uncertain if this vulnerability is reachable or relevant in your specific environment.

CVE advisoryCRITICAL

CVE-2026-69525

Windows Remote Desktop Services Use After Free Vulnerability Allows Network Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical use-after-free vulnerability in Windows Remote Desktop Services may permit an unauthenticated network attacker to execute arbitrary code. This flaw could potentially lead to unauthorized system compromise, impacting integrity and availability. Understanding the exposure of this often internet-facing technolo

CVE advisoryCRITICAL

CVE-2026-69496

Windows Compressed Folder Heap Overflow Allows Network Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical heap-based buffer overflow in Windows Compressed Folders allows an unauthorized attacker to execute code over a network. This could lead to the compromise of system data and services. The relevance and network exposure of this feature within the environment need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-69493

Windows Event Logging Service Out-of-Bounds Read Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An out-of-bounds read in the Windows Event Logging Service enables unauthorized network-based code execution. This affects a core operating system component, posing a significant risk if reachable. Organizations should verify the exposure of this service to understand potential impact.

CVE advisoryCRITICAL

CVE-2026-69491

Windows DirectMusic Heap-Based Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A heap-based buffer overflow in Windows Microsoft DirectMusic may allow an unauthorized attacker to execute code over a network. This vulnerability affects the operating system's multimedia capabilities and, if reachable, could lead to unauthorized code execution.

CVE advisoryCRITICAL

CVE-2026-69463

Windows NTFS Heap Overflow Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical heap-based buffer overflow vulnerability in Windows NTFS allows an unauthorized attacker to execute code over a network. If reachable, this could compromise system integrity and confidentiality. Organizations should assess if their Windows systems are exposed in a way that makes this vulnerability relevant.

CVE advisoryCRITICAL

CVE-2026-69408

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An integer overflow in Windows Media Foundation may allow an attacker to execute code remotely over a network. While the vulnerability could impact system integrity and confidentiality, its relevance is likely limited as the technology is typically used for local media processing rather than being directly exposed to t

CVE advisoryCRITICAL

CVE-2026-69356

Microsoft Exchange Server Cross-Site Scripting Spoofing Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has a cross-site scripting vulnerability that allows an attacker to perform spoofing over a network. This could allow an unauthorized attacker to impersonate legitimate communications by injecting malicious web page elements, potentially impacting user interactions and sender identity.

CVE advisoryCRITICAL

CVE-2026-69276

Microsoft UxTheme Library Integer Underflow Leads to Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer underflow vulnerability exists in the Microsoft UxTheme Library, which handles Windows visual styles. If reachable, an unauthorized attacker could potentially execute code over a network. The relevance and potential impact depend on whether this component is exposed to network-based exploitation in your envi

CVE advisoryCRITICAL

CVE-2026-68839

Windows USB Mass Storage Driver Network Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Windows USB Mass Storage Class Driver could allow an attacker to execute code over a network. This heap-based buffer overflow poses a significant risk if reachable, enabling remote code execution and potential compromise of system integrity and confidentiality. Confirmation of relevance

CVE advisoryCRITICAL

CVE-2026-65669

SQL Server Privilege Escalation via Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network through improper handling of special elements. This could potentially impact data integrity and confidentiality. It is uncertain if affected systems are reachable or relevant in your environment.

CVE advisoryCRITICAL

CVE-2026-82533

DeepSeek Harness Authentication Bypass via Host Header Spoofing

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

DeepSeek Harness has a critical authentication bypass vulnerability in its local HTTP control-plane API. An attacker can exploit this by spoofing a Host header to gain full agent control, execute privileged commands, and retrieve stored conversations. This impacts the integrity and confidentiality of data managed by th

CVE advisoryCRITICAL

CVE-2026-79570

mfish-nocode-pro tableName SQL Injection.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the mfish-nocode-pro database connectivity feature, allowing attackers to access sensitive data via crafted SQL statements. This issue is reachable through network-accessible API endpoints, posing a risk of unauthorized database information disclosure. Identifying product usage a

CVE advisoryCRITICAL

CVE-2026-79569

Movie Recommend v1.0.0 SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in the Movie_Recommend application's sorting parameter allows attackers to access sensitive database information. This external threat, accessible via the network without authentication, could lead to unauthorized data exposure if the application is in use.

CVE advisoryCRITICAL

CVE-2026-78997

UC Browser for Android Universal XSS via JavaScript Bridge

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

UC Browser for Android has a critical vulnerability allowing universal cross-site scripting. An attacker could craft a malicious URL that, when visited by a user, executes arbitrary JavaScript in the context of other websites. This could lead to the compromise of user sessions or data on those sites, making it importan

CVE advisoryCRITICAL

CVE-2026-75156

Apache Airflow FAB Provider Azure AD Token Validation Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Apache Airflow's FAB provider allows unauthenticated access to the Airflow UI by enabling attackers to forge Azure AD identity tokens. This occurs because the system does not sufficiently validate these tokens, permitting an attacker to authenticate as any user, including administrators, by creating

CVE advisoryCRITICAL

CVE-2026-26084

Fortinet FortiSandbox Improper Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper access control vulnerability in Fortinet FortiSandbox may allow an attacker to access sensitive information via crafted HTTP requests. This could impact the confidentiality of system data. Confirming the use of affected FortiSandbox products is important to assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-86840

Bifrost Pallet Improper Authorization Leading to Commission Inflation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An improper authorization vulnerability exists in Bifrost's `vtoken-minting` and `slpx` pallets, allowing an unauthorized account to mint tokens for an arbitrary channel. This could lead to inflated recorded mint volumes for a channel, causing unfair distribution of protocol commission payments. Readers should care bec

CVE advisoryCRITICAL

CVE-2026-86738

Snipe-IT Superuser CSS Injection Via Custom CSS Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Snipe-IT contains a CSS injection vulnerability in its Custom CSS field due to incomplete sanitization. This allows superusers to plant malicious CSS payloads, potentially exfiltrating CSRF tokens from other superusers and enabling account takeover.

CVE advisoryCRITICAL

CVE-2026-86729

WWBN AVideo Authentication Bypass and Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in WWBN AVideo's API that allows unauthenticated remote attackers to perform unlimited password guessing and take over user accounts. The `get_api_preauthorize` endpoint lacks rate limiting and reveals user ID information, enabling brute-force attacks. This could lead to unauthorized access and c

CVE advisoryCRITICAL

CVE-2026-79574

mpush Gateway Server Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An issue in the mpush gateway server permits attackers to execute arbitrary code by sending a crafted broadcast message. This could impact server availability and integrity if the feature is enabled, posing a critical risk due to potential remote code execution. It is important to confirm the relevance and exposure of

CVE advisoryCRITICAL

CVE-2026-79576

Digital-Infrastructure SSO Component Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in the Single-Sign On component of Digital-Infrastructure. This allows unauthenticated attackers to access the system as any user, including administrators, without a password. Due to the critical severity and network-exploitable nature of SSO systems, this issue could lead

CVE advisoryCRITICAL

CVE-2026-79571

Springboot-project SellerAuthorizeAspect Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in the SellerAuthorizeAspect component allows unauthorized access to seller management interfaces. This could permit attackers to view and modify product information, orders, and categories without proper authentication. Confirm relevance and exposure to seller interfaces.

CVE advisoryCRITICAL

CVE-2026-61516

Netis NX10 Credential Disclosure Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Netis NX10 firmware allows unauthenticated attackers to retrieve administrator credentials by accessing a web interface function. This exposure enables unauthorized users to gain full administrative control of the device. Confirming deployment and exposure of these devices is crucial for risk assessm

CVE advisoryCRITICAL

CVE-2026-12745

Ivanti Neurons for ITSM Untrusted Data Deserialization Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Ivanti Neurons for ITSM allows unauthenticated attackers to execute arbitrary code remotely on the server. This occurs due to deserialization of untrusted data, potentially impacting service integrity and availability when exposed.

CVE advisoryCRITICAL

CVE-2026-12744

Ivanti Neurons for ITSM Deserialization Vulnerability Allows Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical deserialization vulnerability in Ivanti Neurons for ITSM allows unauthenticated remote attackers to execute arbitrary code on the server. This could compromise the integrity and availability of the affected system. Organizations using this platform should confirm its relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-12646

Ivanti Neurons for ITSM Missing Authorization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Missing Authorization vulnerability in Ivanti Neurons for ITSM allows an authenticated remote attacker to execute arbitrary code on the server. This could impact server-side operations and potentially lead to unauthorized access or modification of system data.

CVE advisoryCRITICAL

CVE-2026-12645

Ivanti Neurons for ITSM Missing Authorization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Ivanti Neurons for ITSM allows authenticated attackers to execute arbitrary code on the server. This could compromise the confidentiality, integrity, and availability of the IT service management platform. The primary concern is to confirm if affected systems are reachable and relevant to yo

CVE advisoryCRITICAL

CVE-2026-73312

XenForo Refresh Token Replay Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A refresh token replay vulnerability in XenForo allows attackers to reuse tokens to gain persistent unauthorized access due to a failure to mark tokens as consumed after access token expiration. This could lead to repeated generation of new tokens, granting unauthorized access for the token's lifetime. This is relevant

CVE advisoryCRITICAL

CVE-2026-73311

XenForo OAuth2 Authorization Code Reuse Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in XenForo's OAuth2 implementation allows for authorization code reuse, enabling attackers to obtain unauthorized token pairs. This could lead to duplicated user access by exploiting a failure to invalidate used authorization codes. Confirmation of XenForo usage and its OAuth2 functionality is needed to

CVE advisoryCRITICAL

CVE-2026-73309

XenForo OAuth2 Authentication Bypass via Empty Secret and Code Verifier

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in XenForo's OAuth2 token endpoint allows unauthenticated attackers to obtain valid token pairs by submitting empty values for specific parameters, bypassing security validation. This could lead to unauthorized access. The issue is likely to affect forum software instances accessible via the internet.

CVE advisoryCRITICAL

CVE-2026-77089

Command Center API Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Command Center API, allowing authentication bypass and impacting privilege management. If reachable, this could permit unauthorized access and control over system resources without requiring any credentials. Confirming the relevance and exposure of this technology within your envi

CVE advisoryCRITICAL

CVE-2026-78234

Hawtio Operator Allows Certificate Impersonation Using Service CA Key.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical flaw in hawtio-operator allows authenticated users with edit access in any namespace to impersonate in-cluster services by minting forged certificates. This could lead to unauthorized access to components that trust the Service CA for client authentication. Uncertainty exists regarding specific exploitation

CVE advisoryCRITICAL

CVE-2026-71377

Cosminexus Component Container Command Argument Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command argument injection vulnerability exists in Cosminexus Component Container, potentially allowing attackers to execute arbitrary commands. This could impact system integrity and availability if the technology is reachable. Confirmation of its presence and exposure within the environment is necessary.

CVE advisoryCRITICAL

CVE-2026-71376

Cosminexus Component Container OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS command injection vulnerability in Cosminexus Component Container may allow an attacker to execute arbitrary operating system commands. This could lead to unauthorized actions and system compromise if the affected technology is reachable. This is a critical issue affecting core application server technology.

CVE advisoryCRITICAL

CVE-2026-62647

Reyrolle 7SR5 Predictable Random Number Generator Vulnerability Allows Impersonation.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Reyrolle devices allows an unauthenticated attacker to predict security-related values, potentially enabling impersonation and unauthorized access. This could occur if the affected device is remotely accessible. Confirming network exposure and device criticality is advised.

CVE advisoryCRITICAL

CVE-2026-62646

Reyrolle 7SR5 Predictable Session Identifiers Allow Remote Authentication Bypass

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Reyrolle 7SR5 technology allows unauthenticated remote attackers to bypass authentication by predicting session identifiers. This could permit unauthorized access to the device. You should care because this could affect sensitive industrial control systems.

CVE advisoryCRITICAL

CVE-2026-62645

Reyrolle 7SR5 Authentication Bypass via Session ID Exposure.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Reyrolle 7SR5 web interfaces allows unauthorized access by exposing session ID calculation. This could enable an attacker to bypass authentication and gain unauthorized access. Confirming if this technology is in use and its network exposure is crucial due to the specialized nature of the af

CVE advisoryCRITICAL

CVE-2026-71374

Cosminexus Component Container Untrusted Data Deserialization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in Cosminexus Component Container could allow an attacker to execute unauthorized code by sending specially crafted data over the network. This impacts the integrity and availability of application servers. Readers should care because this could lead to system compromise if the affected

CVE advisoryCRITICAL

CVE-2026-76969

SAP CAP MTXSS Credential Exposure and Tenant Data Tampering Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the SAP CDS multi-tenant extensibility library allows unauthenticated attackers to obtain sensitive credentials. This could enable them to replace or delete tenant data, impacting application availability and integrity, with potential partial impact on data confidentiality.

CVE advisoryCRITICAL

CVE-2026-66768

SAP GUI for Java Trust Policy Bypass Allows Command Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in SAP GUI for Java allows a low-privileged attacker to execute arbitrary commands on a user's machine by manipulating a connected backend system. This bypasses trust policy enforcement and could severely impact confidentiality, integrity, and availability. Understanding the relevance of SAP GUI for Jav

CVE advisoryCRITICAL

CVE-2026-58240

SAP NetWeaver Message Server Component Registration Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

SAP NetWeaver Message Server can be exploited by an unauthenticated attacker with network access to register an unauthorized component due to insufficient validation of internal component authenticity. This could allow the attacker to perform unauthorized actions, impacting the confidentiality, integrity, and availabil

CVE advisoryCRITICAL

CVE-2026-44756

Extended Passport Protocol Memory Safety Vulnerability Allows Unauthenticated Network Attacks.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A memory safety vulnerability in the Extended Passport Protocol processing library can be exploited by an unauthenticated network attacker through a crafted request with a malformed EPP header, potentially leading to abnormal program termination and high impact on application confidentiality, integrity, and availabilit