NVD disclosure day

Published threat advisories for September 12, 2026

CVE advisoryCRITICAL

CVE-2026-78159

The Events Calendar WordPress Plugin Remote Code Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in The Events Calendar WordPress plugin allows unauthenticated attackers to execute code on the server. This occurs due to insufficient validation of widget classes, potentially triggered by specially crafted comments on posts when comments are enabled. The ability for an attacker to run their

CVE advisoryCRITICAL

CVE-2026-78006

The Events Calendar WordPress Plugin Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Events Calendar plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. This is possible through specially crafted comments on event pages when comments are enabled and visible, by bypassing security checks during widget rendering.

CVE advisoryCRITICAL

CVE-2026-87719

GitLab Duo Chat GraphQL Subscription Argument Allows Sensitive Data Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

GitLab's Duo Chat feature contains a vulnerability that may allow an authenticated user to obtain sensitive instance configurations and credentials. This occurs when a specially crafted GraphQL subscription argument bypasses serialization, enabling server object lookup. This issue is relevant if your organization uses

CVE advisoryKnown Exploit

CVE-2026-85706

GitLab Path Traversal Allows Arbitrary File Read

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

GitLab instances are affected by a path traversal vulnerability in the repository commits API that can allow unauthenticated users to read arbitrary files from the server. This could lead to unauthorized disclosure of sensitive data, making it important to assess the exposure and business criticality of all deployed Gi

• CISA KEV