NVD disclosure day

Published threat advisories for September 9, 2026

CVE advisoryCRITICAL

CVE-2026-88069

Pandora Path Traversal in Archive Extraction Worker

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Pandora's archive extraction worker has a path traversal vulnerability, allowing crafted archives to write files outside intended directories. This could lead to unauthorized modification of system files, denial of service, or further compromise. It's important to confirm if Pandora is in use and assess its exposure to

CVE advisoryCRITICAL

CVE-2026-71805

LZ-litchi Arbitrary File Upload and Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

LZ-litchi has a critical arbitrary file upload and path traversal vulnerability, allowing unauthenticated remote attackers to write files to any location on the server. This could lead to system compromise if the file upload API is reachable. Readers should care because unauthorized file placement can have severe conse

CVE advisoryCRITICAL

CVE-2026-36433

Actions Semiconductor Media Player Utilities Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Actions Semiconductor Media Player Utilities, allowing physically proximate attackers to execute arbitrary code via Production.dll and RdiskUpgrade.exe. While the risk is considered very unlikely due to the need for physical access and local components, confirmation of software usage

CVE advisoryCRITICAL

CVE-2026-87911

Amazon awslabs postgres-mcp-server OS Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical OS command injection vulnerability exists in the SQL validation component of Amazon awslabs postgres-mcp-server. An unauthenticated actor could exploit this by submitting crafted data to execute operating system commands on the host of a self-managed PostgreSQL server, potentially leading to significant comp

CVE advisoryCRITICAL

CVE-2026-54694

SkillTree Cross-Site Scripting and Request Forgery Vulnerabilities

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The SkillTree gamification platform contains vulnerabilities that could allow an attacker to execute arbitrary code or steal sensitive tokens within an administrator's browser. These flaws are exploitable through account registration and occur when an administrator views the Quiz Runs page. Attackers could potentially

CVE advisoryCRITICAL

CVE-2026-87930

MaxSite CMS Session Cookie Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MaxSite CMS contains a critical vulnerability where it processes session cookies insecurely, allowing unauthenticated attackers to inject PHP objects using a hardcoded encryption key. This could lead to corrupted application state or code execution. It's important to determine if this technology is in use and accessibl

CVE advisoryCRITICAL

CVE-2026-87929

MaxSite CMS Authentication Bypass Via Hardcoded Session Key

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MaxSite CMS has a security vulnerability where a hardcoded session encryption key allows unauthenticated attackers to forge administrator session cookies. This could grant unauthorized administrative access. Confirm if this technology is in use and assess any potential exposure.

CVE advisoryCRITICAL

CVE-2026-47156

MantisBT SOAP API Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass vulnerability exists in the SOAP API of the MantisBT bug tracking system. An attacker knowing a valid cookie string and username can impersonate any user, including administrators, without needing their password. This could lead to unauthorized access to sensitive data and system functi

CVE advisoryCRITICAL

CVE-2026-79689

Dell Secure Connect Gateway OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS Command Injection vulnerability exists in Dell Secure Connect Gateway. Unauthenticated remote attackers could exploit this to inject scripts, potentially leading to unauthorized script execution and compromised system behavior. Organizations should confirm if this technology is deployed and assess potenti

CVE advisoryCRITICAL

CVE-2026-67403

Cash Collect Sage AR Automation API Improper Authorization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability in the Sage AR Automation API allows authenticated users to access administrative resources from other tenants by providing a valid tenant identifier. This could lead to unauthorized access to sensitive business information across different accounts. It is important to determine

CVE advisoryCRITICAL

CVE-2026-22590

Fast DDS Out-of-Bounds Read in RTPS DATA_FRAG Processing Allows Heap Memory Leak

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An out-of-bounds read vulnerability in eProsima Fast DDS allows remote attackers to access sensitive heap memory by sending crafted network messages. This could lead to information disclosure, potentially aiding attackers in bypassing security measures. Readers should confirm if their environment uses this technology a

CVE advisoryCRITICAL

CVE-2026-79941

Dell Secure Connect Gateway Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Dell Secure Connect Gateway has a command injection vulnerability, allowing unauthenticated remote attackers to inject scripts. This could impact system confidentiality, integrity, and availability, making it important to identify and assess any deployed instances.

CVE advisoryCRITICAL

CVE-2026-85102

Check Point Quantum Security Gateway Improper Certificate Trust Validation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Check Point Quantum Security Gateways, related to improper certificate trust validation during VPN negotiation, could allow an unauthenticated remote attacker to execute arbitrary code on the gateway, impacting network security.

CVE advisoryCRITICAL

CVE-2026-87806

Parse Server LDAP Authentication Bypass via Empty Password

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Parse Server deployments using the LDAP authentication adapter are vulnerable to an authentication bypass. Attackers can exploit this by supplying an empty password for a known username, potentially leading to account takeover if the directory accepts unauthenticated simple binds. This affects only specific configurati

CVE advisoryCRITICAL

CVE-2026-80172

Dell SCG Insufficient Data Authenticity Vulnerability Allows Unauthorized Admin Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell Secure Connect Gateway technology has an authentication vulnerability. An unauthenticated remote attacker can gain administrative access by reusing captured requests, allowing for indefinite unauthorized control. This issue is critical because it can lead to unauthorized access and system manipulation.

CVE advisoryCRITICAL

CVE-2026-87827

KGUARD DVR Unauthenticated System Command Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Certain KGUARD DVR devices are vulnerable to unauthenticated system command execution, allowing remote attackers to compromise the device. This issue has been exploited in the wild by botnets. The potential impact includes device compromise and subsequent malicious activity.

CVE advisoryCRITICAL

CVE-2026-85978

Akana API Platform Policy Manager Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Akana API Platform's Policy Manager console allows unauthenticated remote code execution. This occurs when a crafted request bypasses authentication, leading to the execution of attacker-supplied script code. This could enable an attacker to run arbitrary commands on the system without n

CVE advisoryCRITICAL

CVE-2026-56207

Apache Impala SAML2 Authentication Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Apache Impala's SAML2 authentication allows attackers to alter usernames and impersonate other users by bypassing signature verification for the hs2-http interface. If this interface is reachable, unauthorized users could gain access and potentially impact data processed by Impala.

CVE advisoryCRITICAL

CVE-2026-41871

Apache Nutch Server Unsafe Reflection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing authorization vulnerability in the Apache Nutch Server's REST API could allow unauthenticated attackers to execute arbitrary code or commands by sending specially crafted input. This may lead to unauthorized access and modification of the system or its data.

CVE advisoryCRITICAL

CVE-2026-41869

Apache Nutch REST API Missing Authorization and Resource Handling Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The Apache Nutch Server's REST API has a vulnerability allowing unauthenticated network access that could lead to denial-of-service or unauthorized resource access. This affects Nutch versions 1.10 through 1.22, and organizations should verify their usage and restrict access if an upgrade is not immediately possible.

CVE advisoryCRITICAL

CVE-2026-79696

Google Cloud ADK for Python Code Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical code injection vulnerability in Google Cloud's Python development toolkit allows unauthenticated attackers to execute arbitrary code via a crafted test session replay, potentially impacting Cloud Run and GKE environments if the pytest tool is installed.

CVE advisoryCRITICAL

CVE-2026-16272

PayTR WHMCS Module Trusted Identifier Exploitation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the PayTR Virtual Pos iFrame API WHMCS Module, enabling the exploitation of trusted identifiers. This flaw could allow attackers to compromise confidentiality and integrity by sending crafted requests. Understanding the module's reachability and business criticality is important due t

CVE advisoryCRITICAL

CVE-2026-21096

libimagecodec Heap Overflow Allows Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical heap-based buffer overflow vulnerability in a JPEG decoder library could allow remote attackers to execute arbitrary code. This affects systems processing image files, potentially leading to significant compromise if exploited through specially crafted JPEG data. The relevance of this issue depends on the re

CVE advisoryCRITICAL

CVE-2026-21095

DNG Decoder Heap Buffer Overflow Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap-based buffer overflow in the DNG decoder of libimagecodec.quram.so, present in versions before the September 2026 security release, could permit remote attackers to execute arbitrary code. This vulnerability may be triggered by processing a crafted DNG image file, posing a risk of code execution on affected syst

CVE advisoryCRITICAL

CVE-2026-87650

Google Chrome WebGL Out of Bounds Read Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's WebGL component could enable a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. This impacts a widely used web browser, raising concerns about potential exposure during normal internet browsing. Uncertainty exists regarding specific exploitable co

CVE advisoryCRITICAL

CVE-2026-87637

Chrome Extension Use After Free Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome extensions could allow attackers to execute arbitrary code outside the sandbox via a crafted HTML page, requiring user interaction. The relevance to specific environments and user bases is currently uncertain due to its client-side nature.

CVE advisoryCRITICAL

CVE-2026-87634

Chrome WebPackaging Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's WebPackaging component could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, requiring user interaction. The Chromium security severity is Low, but the CVSS base score is Critical. Confirming the reachability and relevance

CVE advisoryCRITICAL

CVE-2026-87621

ANGLE Out of Bounds Write Vulnerability in Google Chrome Leads to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write in Google Chrome's ANGLE component on Windows could allow a remote attacker to execute arbitrary code by convincing a user to visit a crafted HTML page. This vulnerability could affect the confidentiality, integrity, and availability of the user's system.

CVE advisoryCRITICAL

CVE-2026-87613

Google Chrome Extension Reference Resolution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An issue exists in Google Chrome's Extensions component that could allow remote attackers to execute arbitrary code outside the sandbox via crafted network traffic. This vulnerability, impacting how extensions resolve references, could potentially affect system data and service behavior if exploited. Further confirmati

CVE advisoryCRITICAL

CVE-2026-87609

Chrome iOS Sharing Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Chrome's Sharing component on iOS may allow remote attackers to execute arbitrary code outside the sandbox via crafted network traffic. This issue could affect the confidentiality, integrity, and availability of the device. Uncertainty remains regarding the relevance of this vulnerabil

CVE advisoryCRITICAL

CVE-2026-87607

Google Chrome Use-After-Free Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in Google Chrome on Mac allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact the confidentiality, integrity, and availability of the affected system.

CVE advisoryCRITICAL

CVE-2026-87581

Google Chrome Payments Use After Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Payments component could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, requiring user interaction through social engineering.

CVE advisoryCRITICAL

CVE-2026-87558

Chrome Payments Use After Free Leads to Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's payments component allows a remote attacker to execute arbitrary code outside the sandbox by directing a user to a malicious HTML page. This could potentially impact user data processed by the browser.

CVE advisoryCRITICAL

CVE-2026-87547

Google Chrome FileSystem Vulnerability Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's FileSystem could allow a remote attacker to execute arbitrary code outside the sandbox via a malicious HTML page, a situation requiring user interaction. This could lead to compromised data or systems if the affected components are in use and user interaction is possible.

CVE advisoryCRITICAL

CVE-2026-87544

Google Chrome Extension Authorization Bypass in Privileged Page

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An incorrect authorization flaw exists in Google Chrome extensions. This could allow a remote attacker to bypass system access restrictions and access a privileged page by directing a user to a crafted HTML page. The impact on user data or system integrity is uncertain.

CVE advisoryCRITICAL

CVE-2026-87534

Google Chrome Android WebView Authorization Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical authorization flaw exists in Google Chrome's Android WebView, enabling remote attackers to bypass system restrictions via crafted network traffic and social engineering. This vulnerability could impact user data and service behavior if reachable.

CVE advisoryCRITICAL

CVE-2026-87529

Chrome Numeric Truncation Vulnerability Allows Sandbox Escape

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A numeric truncation error in Google Chrome's media component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This vulnerability could impact the confidentiality, integrity, and availability of a user's system.

CVE advisoryCRITICAL

CVE-2026-87528

Google Chrome Type Confusion Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A type confusion vulnerability in Google Chrome could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page on Windows. This could lead to unauthorized actions on the affected system. Chrome has been updated to address this issue.

CVE advisoryCRITICAL

CVE-2026-87527

Chrome WebGL Buffer Overflow Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability in Google Chrome's WebGL component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact the confidentiality, integrity, and availability of user systems.

CVE advisoryCRITICAL

CVE-2026-87526

Google Chrome Use After Free Vulnerability Allows Code Execution Via UI Interaction

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome could allow a remote attacker to execute arbitrary code outside the sandbox by leveraging social engineering and user interaction with the UI. This could potentially impact the confidentiality and integrity of system data.

CVE advisoryCRITICAL

CVE-2026-87512

ANGLE Use After Free Vulnerability in Chrome on Windows

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in ANGLE, a graphics component within Google Chrome, could allow a remote attacker to execute arbitrary code on a user's system by tricking them into visiting a malicious HTML page. This means a crafted webpage could lead to code execution outside the browser's security sandbox.

CVE advisoryCRITICAL

CVE-2026-87494

Google Chrome Use-After-Free Vulnerability Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the sandbox by tricking users into visiting a crafted HTML page. This requires user interaction and social engineering to exploit. It is important to identify if affected browser versions are in use and potentially

CVE advisoryKnown Exploit

CVE-2026-87491

Google Chrome V8 Out of Bounds Write Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An out-of-bounds write vulnerability in Google Chrome's V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page. This could impact browser integrity and potentially lead to unauthorized code execution within the sandbox.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-87488

Google Chrome for Android WebGL Use-After-Free Vulnerability Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome for Android's WebGL component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This impacts user devices if they visit a malicious webpage.

CVE advisoryCRITICAL

CVE-2026-87474

Google Chrome Payments Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in Google Chrome's Payments component. This could allow a remote attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a crafted HTML page. This matters because it could potentially compromise user data or system functions within the browser's isol

CVE advisoryCRITICAL

CVE-2026-87464

Google Chrome WebGL Use After Free Allows Remote Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical use-after-free vulnerability in Google Chrome's WebGL component allows remote attackers to execute arbitrary code outside the sandbox by directing users to a malicious HTML page. This client-side vulnerability, if exploited, could impact system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-87438

Google Chrome WebGL Out of Bounds Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Google Chrome's WebGL component on Android, allowing remote attackers to execute arbitrary code outside the sandbox by directing users to a crafted HTML page. The WebGL implementation in this widely used web browser is susceptible to an out-of-bounds write flaw, which, if triggered, c