NVD disclosure day

Published threat advisories for September 11, 2026

CVE advisoryCRITICAL

CVE-2026-90456

Inventory Component Administrative Interface Exposed by Default Password

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An inventory-management component is affected by a vulnerability where an example configuration file contains a fixed, publicly known administrative password. If this example file is copied into active configuration without regenerating credentials, the component's administrative interface may be exposed to unauthorize

CVE advisoryCRITICAL

CVE-2026-53952

GetSimple CMS Unauthenticated Administrator Account Creation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A logic flaw in GetSimple CMS allows unauthenticated attackers to create new administrator accounts by exploiting a bug in the setup script's deletion process, potentially leading to unauthorized control over the content management system. The vulnerability arises because a security control intended to remove the `admi

CVE advisoryCRITICAL

CVE-2026-79395

Xiongmai IP Camera Sofia IPC Daemon Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authentication flaw in Xiongmai IP Camera firmware's Sofia IPC daemon allows unauthenticated remote attackers to bypass security controls. This could enable unauthorized execution of privileged actions, such as controlling camera functions or rebooting the system. Uncertainty exists regarding specific produ

CVE advisoryCRITICAL

CVE-2026-62105

ThemeREX Addons PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A PHP object injection vulnerability exists in ThemeREX Addons that could allow unauthenticated attackers to execute arbitrary code. This impacts public-facing web applications, potentially leading to full website compromise if reachable. It is important to identify any instances of the affected plugin.

CVE advisoryCRITICAL

CVE-2026-62103

Everest Forms PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in Everest Forms. If reachable, an attacker could exploit this flaw to compromise systems remotely. This impacts public-facing web forms, requiring confirmation of the plugin's presence and reachability within your environment.

CVE advisoryCRITICAL

CVE-2026-54072

Authorizer open redirect vulnerability in /authorize endpoint.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit an open redirect vulnerability in the Authorizer authentication and authorization server by supplying a malicious redirect URI. This could lead to users being sent to attacker-controlled websites, potentially exposing sensitive tokens. The vulnerability was addressed in version 2

CVE advisoryCRITICAL

CVE-2026-82617

Apache OpenNLP Regex Name Finder Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Apache OpenNLP's text analysis functions could allow an attacker to disrupt service by providing specially crafted input that consumes excessive CPU or causes application threads to crash. This issue affects applications using specific built-in name-finding patterns without requiring authentication o

CVE advisoryCRITICAL

CVE-2026-72709

SPIP Missing Authorization Vulnerability Allows Password Reset

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SPIP contains a missing authorization flaw in administrative endpoints, allowing unauthenticated attackers to reset any user's password, including administrators, by using a valid HMAC-SHA256 nonce. This could lead to unauthorized account takeovers, impacting administrative control and data integrity.

CVE advisoryCRITICAL

CVE-2026-54047

Laci Synchroni Improper Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Laci Synchroni's backend has an improper authentication vulnerability where it trusts a user-provided UID from a local configuration file during OAuth2 login, allowing attackers to impersonate any user and perform actions on their behalf. The issue is resolved in version 1.2.3.

CVE advisoryCRITICAL

CVE-2026-3869

PLC Authentication Algorithm Bypass Affects Confidentiality Integrity and Availability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in programmable logic controllers due to an incorrect authentication algorithm implementation. If reachable, this flaw could compromise the confidentiality, integrity, and availability of the PLC, potentially impacting industrial control processes. This matters because it could enable un

CVE advisoryCRITICAL

CVE-2026-89010

WAVLINK Router Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WAVLINK routers contain an unauthenticated OS command injection vulnerability. Attackers can exploit this by sending crafted filenames to a specific service, potentially executing arbitrary commands as root. This could lead to significant compromise of the network edge.

CVE advisoryCRITICAL

CVE-2026-87988

Mistral Vibe Arbitrary File Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file access vulnerability in Mistral Vibe allows bypassing workspace restrictions via commands classified as unconditionally allowed, potentially exposing sensitive information. Missing path validation enables access to files outside the active workspace without user approval.

CVE advisoryCRITICAL

CVE-2026-87987

Mistral Vibe Command Permission Bypass Allows Arbitrary Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Mistral Vibe contains an arbitrary code execution vulnerability where environment variable assignments preceding allowlisted commands are not inspected, allowing bypass of permission checks and unauthorized code execution. This could enable an attacker to execute arbitrary code without user approval, the potential impa

CVE advisoryCRITICAL

CVE-2026-87986

Mistral Vibe Command Injection via Unparsed Shell Constructs.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Mistral Vibe, allowing attackers to execute arbitrary commands by bypassing permission checks. This occurs when the parser fails to interpret specific shell constructs, enabling uninspected commands to run on the system without authorization. Organizations should verify if Mistral Vib

CVE advisoryCRITICAL

CVE-2026-87985

Mistral Vibe Command Permission Bypass Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An arbitrary code execution flaw exists in Mistral Vibe, where improperly inspected command arguments allow attackers to bypass permission checks and run malicious code on a user's system. This vulnerability is relevant if Mistral Vibe is deployed within your environment and could potentially be exposed, necessitating

CVE advisoryCRITICAL

CVE-2026-87984

Mistral Vibe Arbitrary File Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An arbitrary file write vulnerability in Mistral Vibe allows attackers to create or overwrite files outside the active workspace. This occurs because shell redirection destinations are not properly checked, enabling otherwise permitted commands to write to arbitrary paths accessible by the Vibe process, potentially imp

CVE advisoryCRITICAL

CVE-2026-89212

Akana API Platform XML External Entity Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical XML external entity vulnerability exists in the Akana API Platform due to improper restriction of references during XML-to-JSON processing. This could allow unauthenticated attackers to access sensitive information if the platform is reachable. It is important to confirm if this platform is in use and expose

CVE advisoryCRITICAL

CVE-2026-71644

Robotics-STAR-Lab RACER Unsafe Trajectory Planning Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in drone trajectory planning software may allow an attacker to cause unsafe flight path planning and potential drone collisions. This could occur if the drone enters an idle state, triggering a missing default case that stops swarm trajectory publishing. The impact on operational safety and sys

CVE advisoryCRITICAL

CVE-2026-84390

Fortinet FortiMonitorOnSight Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Fortinet FortiMonitorOnSight may allow an attacker to improperly access sensitive information due to flawed access controls in the source code. If reachable, this could lead to unauthorized access to system data. The absence of a specific attack vector means the exact impact is uncertain, but the pot

CVE advisoryCRITICAL

CVE-2026-80462

Chef Automate API Gateway Unauthenticated Elevated Access Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Chef Automate's API gateway could permit an unauthenticated actor to gain elevated access to protected functionality under specific conditions. This raises concerns for systems using Chef Automate for centralized management and identity services. The potential for unauthorized access to administrativ

CVE advisoryCRITICAL

CVE-2026-89259

Hugo Allows File Access Outside Project Directory via Tailwind CSS

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Hugo, a static site generator, permits Node tools invoked during site builds to read and write files outside the project directory. This occurs when TailwindCSS is used with a permissive configuration, bypassing intended security restrictions. While the issue affects the build process, its reachabili

CVE advisoryCRITICAL

CVE-2026-89258

Hugo Path Traversal via Symlink Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Hugo allows bypassing path confinement through symlinks in parent directories, potentially disclosing unintended files in the built site. This occurs when symlinks are present in mounted directories and accessed via direct resource lookups, though themes fetched as Go modules are unaffected.

CVE advisoryCRITICAL

CVE-2026-89256

AVideo Bookmark Plugin Stored Cross-Site Scripting Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo's Bookmark plugin has a stored cross-site scripting vulnerability where chapter names are not encoded, allowing a video owner to inject malicious scripts that execute in any visitor's browser. This impacts user experience by allowing script execution within the AVideo origin. Uncertainty exists regarding whether

CVE advisoryCRITICAL

CVE-2026-89255

AVideo LoginControl Stored XSS via PGP Public Key

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo's LoginControl plugin has a stored cross-site scripting vulnerability. An authenticated attacker can inject malicious JavaScript via a crafted PGP public key. This script can execute in an administrator's session when their profile is viewed, potentially leading to unauthorized actions. Readers should care becau

CVE advisoryCRITICAL

CVE-2026-89254

AVideo CustomizeUser Plugin Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo's CustomizeUser plugin contains a stored cross-site scripting vulnerability where an attacker with low privileges can inject malicious scripts. These scripts can execute when an administrator views certain pages or profile forms, potentially affecting web application integrity. Confirmation of AVideo usage and i

CVE advisoryCRITICAL

CVE-2026-89253

AVideo Donation Link Stored Cross-Site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WWBN AVideo has a stored cross-site scripting vulnerability in its user donation link feature. If reachable, an authenticated user can inject JavaScript that executes in visitors' browsers when they interact with the donation button on a video watch page, potentially affecting administrators. The exact business impact

CVE advisoryCRITICAL

CVE-2026-89249

AVideo YPTWallet Plugin Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability exists in the AVideo YPTWallet plugin, allowing attackers to perform administrative actions by injecting malicious markup. This occurs when user-supplied CryptoWallet values are not properly escaped before being stored and later displayed to administrators. The threat is crit

CVE advisoryCRITICAL

CVE-2026-89243

WWBN AVideo Stored Cross-Site Scripting Vulnerability in User Group Management.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

WWBN AVideo software has a stored cross-site scripting vulnerability in its user group management feature. An administrator can inject malicious code into group names, which then executes in the browser of other administrators when they access the user manager interface. This requires privileged access and specific use

CVE advisoryCRITICAL

CVE-2026-47839

Federated OIDC Users Bypass Group Restrictions to Gain Admin Scope.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in federated OIDC authentication allows users to gain unintended administrative scope when specific group mapping and wildcard whitelist configurations are used. This could permit unauthorized access to sensitive administrative functions, making it important to verify the configuration of external ident

CVE advisoryCRITICAL

CVE-2026-14563

Advanced-Customized-Prompts WordPress Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the advanced-customized-prompts WordPress plugin enables unauthenticated attackers to bypass password verification, allowing them to log in as any user or create new accounts. This could lead to unauthorized control over WordPress sites and their data.

CVE advisoryCRITICAL

CVE-2026-14560

WordPress Plugin Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin vulnerability allows unauthenticated attackers to upload and execute arbitrary PHP files on a server. This could lead to code execution, impacting website integrity and availability. The issue stems from the plugin's failure to properly validate uploaded files.

CVE advisoryCRITICAL

CVE-2026-14559

WordPress Plugin Allows Unauthorized Administrator Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a WordPress plugin that allows unauthenticated attackers to log in as any registered user, including administrators, by submitting only a user's email address. This could lead to unauthorized administrative control of the website and potential compromise of its integrity and data.

CVE advisoryCRITICAL

CVE-2026-8778

MIPL Grouped Checkout Fields for WooCommerce Arbitrary File Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a WordPress plugin for WooCommerce checkout fields, allowing unauthenticated attackers to upload arbitrary files to the server. This could potentially lead to remote code execution, impacting website integrity and availability. It is important to determine if your site uses this plugi