NVD disclosure day

Published threat advisories for September 13, 2026

CVE advisoryCRITICAL

CVE-2026-81648

CryptoPayment Gateway WordPress Plugin Arbitrary File Deletion and Data Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a WordPress payment gateway plugin allows unauthenticated users to perform administrative operations. This could lead to arbitrary file deletion, modification of payment gateway configurations, and recovery of cleartext wallet credentials, impacting system integrity and data security. The re

CVE advisoryCRITICAL

CVE-2026-90561

Strapi Stored XSS in WYSIWYG Preview Component

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stored cross-site scripting vulnerability exists in Strapi's content manager WYSIWYG preview component, allowing an authenticated author to inject scripts. These scripts can execute within the sessions of higher-privileged users, such as editors or super admins, when they interact with the preview pane, potentially l