NVD disclosure day

Published threat advisories for September 14, 2026

CVE advisoryCRITICAL

CVE-2026-12944

IBM Langflow OSS Python Code Injection Allows Root Privilege Escalation and Data Exfiltration.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS contains a vulnerability allowing attackers to execute arbitrary Python code as root. This can lead to AWS credential theft, data exfiltration, and lateral movement within internal networks. The vulnerability is reachable via network access to the server.

CVE advisoryCRITICAL

CVE-2026-86881

Apple Certificate Validation Flaw Allows Arbitrary Certificate Issuance.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A certificate validation flaw in Apple operating systems could allow an attacker with a compromised intermediate certificate authority to issue fraudulent certificates. This might enable the impersonation of legitimate services, potentially leading to data compromise or unauthorized access. Confirmation of relevance to

CVE advisoryCRITICAL

CVE-2026-84609

Apple OS Permissions Flaw Allows Protected File Modification

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A permissions issue in Apple operating systems allows an app to modify protected system files, impacting system integrity. This vulnerability, fixed in various OS versions, could lead to system instability if exploited. The relevance of this issue depends on the presence of installed applications on affected devices.

CVE advisoryCRITICAL

CVE-2026-84561

Apple iOS and iPadOS Double Free Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory management vulnerability in Apple operating systems may allow an application to cause unexpected system termination or corrupt kernel memory. While this has been addressed in recent software updates, the concern is confirming relevance and exposure to this system-level issue. Users should verify system exposur

CVE advisoryCRITICAL

CVE-2026-67399

WHMCS Deserialization Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Deserialization of untrusted data in WHMCS allows remote attackers to execute arbitrary code. This vulnerability arises when the application processes untrusted data, potentially leading to unauthorized code execution on the server. The primary concern is to identify affected WHMCS installations and assess their exposu

CVE advisoryCRITICAL

CVE-2026-65414

Apple iOS and iPadOS Out-of-Bounds Write Vulnerability Allows Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write vulnerability in Apple operating systems could allow a remote attacker to cause unexpected app termination or execute arbitrary code. This issue is addressed with improved bounds checking. The exact data or systems that could be affected are not specified.

CVE advisoryCRITICAL

CVE-2026-53713

Envoy Gateway Path Traversal Vulnerability Allows Arbitrary File Reading

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unpatched Envoy Gateway can allow an authenticated attacker to read arbitrary files from the gateway controller pod, potentially exposing sensitive credentials. This vulnerability arises from improper handling of redundant path separators before a security check. If exploited, disclosed credentials could grant acces

CVE advisoryCRITICAL

CVE-2026-43790

macOS Kernel Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in macOS could allow remote attackers to cause unexpected system termination or corrupt kernel memory. This vulnerability impacts core operating system functions, and while typically not directly exposed to the internet, its relevance to specific environments requires confirmation.

CVE advisoryCRITICAL

CVE-2026-55209

Resdata GRDECL Parsing Buffer Overflow.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The resdata software, used for processing reservoir simulation files, contains a vulnerability where it insufficiently validates data while parsing GRDECL files. This can lead to memory corruption or service termination if the software is exposed to untrusted files via a network service.

CVE advisoryCRITICAL

CVE-2026-54333

UEFI Firmware Parser Stack Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the UEFI Firmware Parser allows a crafted firmware file to corrupt stack memory, potentially leading to a crash or code execution. The parser handles BIOS, Intel ME, and UEFI firmware structures. This issue is concerning if the parser processes untrusted firmware.

CVE advisoryCRITICAL

CVE-2026-50006

Anyquery SQL Injection Allows Arbitrary File Write and Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An SQL query engine, Anyquery, has a vulnerability allowing unauthenticated remote attackers to create or overwrite files. This can lead to filesystem integrity loss and denial of service, with a possibility of remote code execution depending on other services or process privileges. It is important to confirm if Anyque

CVE advisoryHIGH

CVE-2026-16338

IBM DataStage Arbitrary File Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An arbitrary file write vulnerability exists in IBM DataStage, allowing authenticated users to write files to any location due to improper path validation. This could compromise system integrity if the affected technology is in use and reachable. Organizations should confirm their use of IBM DataStage and assess its ex

CVE advisoryCRITICAL

CVE-2026-59178

ESPHome Device Builder Authentication Loss on Upgrade

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The ESPHome Device Builder Dashboard may lose authentication when upgraded, potentially exposing it to unauthorized access if reachable on a network. This could allow unauthenticated users to interact with device management functions. Confirming its presence and network exposure is advisable.

CVE advisoryCRITICAL

CVE-2026-90942

Casdoor Certificate Endpoint Private Key Exposure Allows Token Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Casdoor's certificate endpoints expose a built-in private key, enabling an organization administrator to forge JWT tokens for any user, including global administrators, across all organizations. This could grant unauthorized access to critical systems.

CVE advisoryCRITICAL

CVE-2026-57578

DotVVM Authorization Filter Bypass Leading to Unauthorized Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The DotVVM framework has an authorization flaw where a filter may fail to perform necessary checks, potentially exposing protected commands, view models, or presenters to unauthorized requests. This issue could allow unauthenticated access to sensitive application features.

CVE advisoryKnown Exploit

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Command Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Cisco Secure Email Gateway's email parsing, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by sending crafted emails. The affected technology is an internet-facing email security gateway, making it reachable for exploitation. Understanding

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-76443

Cisco Secure Email Gateway and Web Manager Improper Neutralization Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cisco Secure Email Gateway and Web Manager products contain vulnerabilities due to improper neutralization. If reachable, an attacker could exploit these flaws, potentially leading to critical impact, such as arbitrary code execution. Organizations using these Cisco products should confirm their relevance and assess po

CVE advisoryCRITICAL

CVE-2026-76441

Cisco Secure Email Improper Access Control Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cisco Secure Email Gateway and Secure Email Manager have improper access control vulnerabilities that allow unauthenticated remote attackers to impact confidentiality, integrity, and availability. These internet-facing products are externally reachable, posing a risk to system configuration and email data.

CVE advisoryCRITICAL

CVE-2026-76440

Cisco Secure Email Gateway Path Traversal Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Path traversal vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated attacker to access or modify sensitive system files. These issues could impact the security of email communications if exploited.

CVE advisoryCRITICAL

CVE-2026-20353

Cisco Secure Email Gateway and Web Manager Resource Lifetime Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cisco Secure Email Gateway and Web Manager have critical resource control vulnerabilities that could allow an unauthenticated attacker to compromise confidentiality, integrity, and availability. It is uncertain if specific products or versions are exploited. The potential impact warrants confirmation of their use and e

CVE advisoryCRITICAL

CVE-2026-90943

Stored XSS in Filament Comments Comment Body Rendering

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A stored cross-site scripting vulnerability exists in a comment rendering component, allowing authenticated users to inject malicious scripts. These scripts execute in the browsers of other users viewing the comments, potentially enabling session token theft and unauthorized actions. The impact is dependent on the comm

CVE advisoryCRITICAL

CVE-2026-57145

PraisonAI Path Traversal Vulnerability Exposes Secrets and Enables Tampering.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the PraisonAI multi-agent system allows prompt-influenced agents to read or overwrite files due to improper handling of file paths. This could lead to the exposure of secrets and application tampering, impacting system integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-57131

PraisonAI API Unauthenticated Job Creation and Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the PraisonAI multi-agent system allows unauthenticated network clients to submit attacker-controlled prompts and agent configurations. This can expose service credentials and connected tool capabilities, potentially leading to unauthorized agent execution. This issue impacts PraisonAI's job

CVE advisoryCRITICAL

CVE-2026-57127

PraisonAI Authentication Bypass Allows Unauthenticated Access to Recipe Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the PraisonAI multi-agent system allows unauthenticated access to recipe execution and tool triggering when API authentication is not properly configured. This could enable unauthorized users to execute connected tools. The relevance and exposure of this vulnerability to your environment sho

CVE advisoryCRITICAL

CVE-2026-57124

PraisonAI UI Unauthenticated Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

PraisonAI's UI host applications have a critical vulnerability allowing unauthenticated network access to execute arbitrary commands. This could lead to system compromise if the affected technology is in use and reachable. Confirm usage and exposure to assess risk.

CVE advisoryCRITICAL

CVE-2026-82435

Apache Storm Netty Decoder Unauthenticated Large Allocation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in a message decoder allows unauthenticated network access to trigger large memory allocations, potentially impacting service availability. The exact effect on worker stability is unmeasured but could lead to resource exhaustion. The primary concern is confirming if this component is deployed a

CVE advisoryCRITICAL

CVE-2026-82434

Apache Storm ZooKeeper Credentials Exposed via Topology Configuration and Logs

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Storm allows unauthorized users with read-only topology permissions to obtain ZooKeeper credentials. These credentials can be used to forge or remove topology state, impacting cluster operations. The credential may also be logged, further increasing exposure. The recommended fix is to upgrade

CVE advisoryCRITICAL

CVE-2026-82431

Apache Storm Nimbus Group Restriction Bypass

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Apache Storm's access control allows any authenticated user to perform unauthorized operations if cluster access is restricted by group alone and no users are specified. This bypasses intended security measures, permitting actions like submitting topologies or accessing cluster configurations. This issue is r

CVE advisoryCRITICAL

CVE-2026-57125

PraisonAI Agents Remote Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the PraisonAI multi-agent system, allowing unauthenticated remote attackers to execute arbitrary operating-system commands. This occurs when specially crafted API requests bypass approval checks, leading to the execution of commands without credentials. Readers should care because thi

CVE advisoryCRITICAL

CVE-2026-57123

PraisonAI Agents Unauthenticated Tool Invocation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in PraisonAI's multi-agent system allows unauthenticated invocation of registered tools, potentially leading to file, shell, or code execution. This arises from certain server components binding to all network interfaces without proper security controls, making them reachable and exploitable via direct

CVE advisoryCRITICAL

CVE-2026-90961

MISP Authentication Bypass Vulnerability in LdapAuth and LinOTPAuth Plugins.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain authentication plugins in MISP allow unauthenticated bypass if an attacker knows a valid user's email address. This can grant unauthorized access with the impersonated user's privileges, including sensitive threat intelligence data. The vulnerability requires the affected plugin to be enabled.

CVE advisoryCRITICAL

CVE-2026-82441

Nimbus Topology Submission Validation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Apache Storm's Nimbus component allows for unvalidated topology submissions, potentially leading to the deletion of critical files or cluster leadership disruption. An attacker could exploit this by submitting a crafted topology with malicious blobstore keys, causing Nimbus to delete other topologies

CVE advisoryCRITICAL

CVE-2026-82439

DRPC Server Heap Exhaustion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in DRPC servers allows unauthenticated attackers to exhaust server memory by sending unique function names, potentially causing a denial of service. The issue occurs because the server retains entries for these names indefinitely, and the default configuration requires no authentication to reach the aff

CVE advisoryCRITICAL

CVE-2026-73370

Apache Syncope Incomplete Authorization on Delegated Administration.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect authorization vulnerability in Apache Syncope allows administrators without adequate permissions to perform unauthorized actions due to incomplete security checks in the Reconciliation service. This could impact system integrity and confidentiality. It is uncertain if specific instances are affected or exp

CVE advisoryCRITICAL

CVE-2026-90937

Froxlor Subdomain Redirect URL Injection allows Nginx Apache Configuration Manipulation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Froxlor fails to validate newline characters in subdomain redirect URLs, allowing authenticated users to inject arbitrary web server configuration directives. This can lead to web server corruption, denial of service, or hijacking of responses for hosted domains.

CVE advisoryCRITICAL

CVE-2026-78330

Apache Syncope Privilege Escalation via JWKS Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An incorrect privilege assignment vulnerability exists in Apache Syncope. If internal JWKS settings for JWT authentication are exposed, an attacker could gain administrative privileges after authenticating with a low-privilege token. This elevates the importance of verifying the relevance and exposure of your Syncope i

CVE advisoryCRITICAL

CVE-2026-78299

Eclipse Embedded CDT Archive Extraction Vulnerability Writes Arbitrary Files

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Eclipse Embedded CDT allows arbitrary file writes if a compromised archive is extracted, potentially overwriting critical files. The exploitation requires user interaction within a developer environment, limiting direct operational impact but still necessitating security review.

CVE advisoryCRITICAL

CVE-2026-77181

Apache Syncope ClientApp Authorization Flaw.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authorization flaw in Apache Syncope could allow unintended changes to client applications by improperly checking permissions. This impacts administrators managing client applications, potentially leading to unauthorized actions if the vulnerability is reachable. The relevance of this issue depends on how Apache Syn

CVE advisoryCRITICAL

CVE-2026-77051

Apache Syncope SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability exists in Apache Syncope, an identity management system, where an administrator with adequate privileges can execute arbitrary SQL commands by exploiting unsanitized parameters. This could lead to unauthorized data access or manipulation within the database.

CVE advisoryCRITICAL

CVE-2026-75030

Apache Syncope Missing Authorization Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Apache Syncope has a critical authorization vulnerability allowing administrators with task execution entitlements to mass (de)provision group members beyond their intended capabilities. This could lead to unauthorized modifications of group memberships, impacting identity management. Confirm Syncope usage and exposure

CVE advisoryCRITICAL

CVE-2026-73668

Apache Syncope Realm Authorization Bypass Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An incorrect authorization vulnerability exists in Apache Syncope. An administrator with adequate entitlements in one realm may be able to read confidential connector configuration from another realm via REST, potentially allowing them to duplicate connector instances. This impacts identity management controls. Confirm

CVE advisoryCRITICAL

CVE-2026-73579

Apache Syncope Authorization Bypass in Search Functionality

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization vulnerability in Apache Syncope can allow unauthorized access to data by bypassing access restrictions during search operations. If reachable, this could lead to unauthorized access to search results, potentially exposing sensitive information. It is important to verify if this software is in use and a

CVE advisoryCRITICAL

CVE-2026-73470

Apache Syncope Improper Privilege Management vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Improper Privilege Management vulnerability in Apache Syncope could allow unauthorized creation or modification of delegations, potentially impacting access controls. This issue may affect the integrity and availability of the system's access control mechanisms. It is important to confirm if Apache Syncope is in use

CVE advisoryCRITICAL

CVE-2026-12258

Hiperdino REST API Information Disclosure Via Inadequate Access Control

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An inadequate access control in Hiperdino’s REST API allows an attacker with a static bearer token to enumerate customer contact details via a public endpoint. This vulnerability could lead to information disclosure of registered users' telephone numbers and email addresses.

CVE advisoryCRITICAL

CVE-2026-90919

LightLLM Config Server Pickle Deserialization Remote Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in LightLLM's Config Server, allowing unauthenticated attackers to execute arbitrary code remotely by sending a malicious serialized payload via a WebSocket endpoint. This could lead to unauthorized control of the server process. Readers should care due to the potential for system compro

CVE advisoryCRITICAL

CVE-2026-90898

Bifrost MCP Client Registration Vulnerability Allows Unauthenticated Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Bifrost's management API allows unauthenticated attackers to register MCP clients and execute arbitrary commands as the Bifrost process. This can occur if authentication is disabled, potentially impacting system integrity and availability.

CVE advisoryCRITICAL

CVE-2026-87802

Apache Syncope SRA JWT Forgery Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper cryptographic signature verification vulnerability in Apache Syncope allows an attacker to forge JWTs, impersonate users, and gain unauthorized access to proxied services when OAuth 2.0 is configured without a JWKS URI. This could lead to the compromise of sensitive data and services.

CVE advisoryCRITICAL

CVE-2026-87785

Apache Syncope JWT Authentication Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache Syncope has an authentication bypass vulnerability where an attacker can spoof user privileges if JWKS settings are disclosed. This could allow unauthorized access to user data and controls. Confirming the exposure and relevance of Syncope deployments is important for security.

CVE advisoryCRITICAL

CVE-2026-86460

Apache Syncope Cypher Injection in Persistence Layer.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Cypher injection vulnerability exists in the Neo4j persistence layer of Apache Syncope when processing specific FIQL search conditions. If reachable, an attacker could exploit this to manipulate database queries, potentially leading to unauthorized access or modification of data.

CVE advisoryCRITICAL

CVE-2026-82232

Apache Syncope SQL Injection in Task Search Sort Clauses

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical SQL injection vulnerability exists in Apache Syncope, allowing an authenticated administrator to execute arbitrary SQL via unsanitized sort clauses in task searches. This could lead to data compromise or unauthorized system control. Confirm if your Syncope instances are affected and if administrative access

CVE advisoryCRITICAL

CVE-2026-90693

D-Link DIR-878 Stack Buffer Overflow in WAN Settings

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical stack-based buffer overflow vulnerability exists in D-Link DIR-878 routers within the WAN Settings function. This flaw can be exploited remotely by an attacker with network access to execute arbitrary code, potentially compromising the device and its network traffic.

CVE advisoryCRITICAL

CVE-2026-90692

D-Link DIR-878 Stack Buffer Overflow in Dynamic DNS IPv6 Settings

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in D-Link DIR-878 devices within the Dynamic DNS IPv6 Settings, allowing remote attackers to trigger a stack-based buffer overflow by manipulating IPv6 address or hostname arguments. This could lead to a compromise of the device's integrity and availability, impacting network stability.

CVE advisoryCRITICAL

CVE-2026-85192

Joomla Conditional Content Extension Authenticated Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in a Joomla extension where authenticated, privileged users can execute remote code by embedding PHP within article content. Publishing such an article triggers the code to run as the web server process, potentially compromising the server and its data. The relevance and exposure of this

CVE advisoryCRITICAL

CVE-2026-90680

D-Link DIR-823G HNAP1 Stack Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability exists in the HNAP1 component of D-Link routers. Remote attackers can exploit this flaw by manipulating network settings, potentially leading to system compromise. It is important to determine if this technology is in use and assess any potential exposure.