NVD disclosure day

Published threat advisories for September 15, 2026

CVE advisoryCRITICAL

CVE-2026-81855

Wärtsilä FOS-Onboard Robot Testing Hardcoded Key Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A hardcoded cryptographic key in the Wärtsilä FOS-Onboard robot testing framework component could allow unauthorized access if the component is reachable. This vulnerability poses a risk to system data integrity and confidentiality. It is important to confirm if this specific component is in use and exposed in your env

CVE advisoryCRITICAL

CVE-2026-78225

Wärtsilä FOS-Onboard Update Controller Hardcoded Key Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A hardcoded cryptographic key in Wärtsilä FOS-Onboard's Update Controller could allow unauthorized access, potentially compromising system integrity and confidentiality. This vulnerability's relevance depends on whether the affected technology is in use and accessible. The risk is associated with system data and servic

CVE advisoryCRITICAL

CVE-2026-73807

mySCADA myPRO Manager API Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the mySCADA myPRO Manager command API, allowing unauthenticated network access to privileged functions. This could enable an attacker to manipulate sensitive management operations without proper credentials, potentially impacting system control and configuration.

CVE advisoryCRITICAL

CVE-2026-61560

Unauthenticated File Read in @zereight/mcp-gitlab Allows GitLab Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in `@zereight/mcp-gitlab` that allows unauthenticated attackers to read arbitrary files from the server. If the SSE transport mode is enabled, which is the default in Docker deployments, this could lead to the exposure of sensitive information like `GITLAB_PERSONAL_ACCESS_TOKEN`, potentially enab

CVE advisoryCRITICAL

CVE-2026-91939

Cotonti Comments Plugin PHP Object Injection leads to Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cotonti's Comments plugin is vulnerable to PHP object injection, allowing unauthenticated attackers to instantiate arbitrary PHP classes, potentially leading to database manipulation or code execution. This issue is reachable via the network and poses a critical risk.

CVE advisoryCRITICAL

CVE-2026-91749

Chrome Workers Use After Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability in Google Chrome's Workers feature allows remote attackers to potentially execute arbitrary code outside the sandbox via a crafted HTML page. This requires user interaction with a malicious website and could impact the confidentiality, integrity, and availability of the user's system. The

CVE advisoryCRITICAL

CVE-2026-91738

ANGLE Input Validation Flaw in Chrome Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Chrome's ANGLE component may allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. This could impact system security when browsing malicious web content. Confirming relevance and managing browser updates is important.

CVE advisoryCRITICAL

CVE-2026-91716

Google Chrome Use After Free in Authentication Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in Google Chrome's authentication process could allow an unauthenticated remote attacker to execute arbitrary code outside the sandbox by directing a user to a malicious HTML page. This presents a risk of system compromise and potential data exposure.

CVE advisoryCRITICAL

CVE-2026-91710

Chrome Use After Free in WebAppInstalls Allows Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A use-after-free vulnerability exists in Chrome's WebAppInstalls component, potentially allowing a remote attacker to execute arbitrary code outside the browser's sandbox. This could occur if a user visits a malicious HTML page. The impact depends on whether users access untrusted web content and requires confirmation

CVE advisoryCRITICAL

CVE-2026-68491

SolusVM Arbitrary File Overwrite Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An insufficient check allows an authenticated user in a virtual machine to overwrite arbitrary host files using a symbolic link. This could lead to guest-to-host privilege escalation. The relevance and exposure to your infrastructure need to be confirmed.

CVE advisoryCRITICAL

CVE-2026-61568

GitLab MCP Streamable HTTP Endpoint Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the `@zereight/mcp-gitlab` Model Context Protocol server could allow a malicious webpage to bypass security controls using DNS rebinding, potentially leading to unauthorized access to local MCP listeners. This issue arises because the server may not effectively validate the `Host` or `Origin` headers

CVE advisoryCRITICAL

CVE-2026-61559

GitLab MCP Server Token Leak Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in `@zereight/mcp-gitlab` when a specific environment variable is enabled, allowing attackers to redirect GitLab API calls to malicious hosts and intercept user authentication tokens. If reachable, this could expose sensitive GitLab tokens and lead to unauthorized access. This affects backend ser

CVE advisoryCRITICAL

CVE-2026-54337

Fireshare Argument Injection Allows Unauthenticated System File Manipulation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An argument injection vulnerability in Fireshare's video upload function allows unauthenticated attackers to write or overwrite system files. This could impact system integrity and availability if the affected technology is reachable. Confirmation of its use within the organization is advised to assess potential exposu

CVE advisoryCRITICAL

CVE-2026-89040

Tencent MSEC Remote Code Execution and Root Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Tencent Mass Service Engine in Cluster is vulnerable to remote code execution and root access. An unauthenticated attacker can exploit this by sending a crafted POST request to gain root privileges and execute arbitrary code. This affects core infrastructure and service management.

CVE advisoryCRITICAL

CVE-2026-87230

Oracle Hyperion Financial Management Authentication Bypass Allows Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management, allowing unauthenticated attackers with network access to potentially compromise sensitive financial data. Successful exploitation could result in unauthorized creation, deletion, or modification of critical data, and may impact other connected Or

CVE advisoryCRITICAL

CVE-2026-87223

Oracle Hyperion Financial Management Security Vulnerability Allows Data Manipulation and Denial of Service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Hyperion Financial Management could allow an unauthenticated attacker with network access to modify or delete critical financial data and cause a denial of service. This impacts the integrity and availability of financial information.

CVE advisoryCRITICAL

CVE-2026-87217

Oracle Hyperion Financial Management Security Vulnerability Allows Unauthorized Data Access and Modification.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management that allows unauthenticated attackers with network access to compromise the system. Successful exploitation could lead to unauthorized creation, deletion, modification, or complete access to critical financial data. This issue is relevant due to th

CVE advisoryCRITICAL

CVE-2026-87214

Oracle Hyperion Financial Management High Privilege Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management, allowing a highly privileged attacker with network access to potentially compromise the system. Successful exploitation could lead to a full takeover of the application, impacting other connected products. Understanding your deployment's relevance

CVE advisoryCRITICAL

CVE-2026-87189

Oracle Hyperion Financial Management High Privilege Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Hyperion Financial Management allows a highly privileged attacker with network access to compromise the system. Exploitation could lead to a complete takeover of the financial management environment and potentially impact other connected products. This issue merits attention due to th

CVE advisoryCRITICAL

CVE-2026-87188

Oracle Hyperion Financial Management Unauthenticated Network Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management that allows unauthenticated attackers with network access to take over the system. This could compromise sensitive financial data and reporting integrity. Confirming if this product is in use and accessible is crucial.

CVE advisoryCRITICAL

CVE-2026-87184

Oracle Hyperion Financial Management SQL Injection Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management, allowing unauthenticated attackers with network access to compromise the application through SQL injection. Successful exploitation could lead to a complete takeover of the system, impacting confidentiality, integrity, and availability. This is a

CVE advisoryCRITICAL

CVE-2026-87176

Oracle Hyperion Financial Management Security Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized access, modification, or deletion of critical financial data. This issue impacts data integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2026-87175

Oracle Hyperion Financial Management Security Vulnerability Allows Unauthorized Data Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Hyperion Financial Management could allow an unauthenticated attacker with network access to compromise the system. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical financial data. This issue is relevant for organizations using this fi

CVE advisoryCRITICAL

CVE-2026-87173

Oracle Hyperion Financial Management Security Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management, allowing unauthenticated attackers with network access to compromise the product. This could lead to unauthorized creation, deletion, or modification of critical financial data, or complete access to all accessible data. The CVSS 3.1 score is 9.1,

CVE advisoryCRITICAL

CVE-2026-87172

Oracle Hyperion Financial Management Security Vulnerability Allows Full Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Hyperion Financial Management, allowing a low-privileged attacker with network access to compromise the system. Successful exploitation could lead to a full takeover of the application, potentially impacting other connected products and sensitive financial information. Confirmi

CVE advisoryCRITICAL

CVE-2026-87170

Oracle Hyperion Financial Management Security Vulnerability Allows Unauthorized Data Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Oracle Hyperion Financial Management that allows unauthenticated attackers with network access to gain unauthorized access to critical financial data. Successful exploitation could lead to unauthorized creation, deletion, or modification of sensitive information, impacting data integrity and c

CVE advisoryCRITICAL

CVE-2026-87129

Oracle Hyperion Data Relationship Management Access Control Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker with network access can compromise Oracle Hyperion Data Relationship Management, potentially leading to unauthorized access, deletion, or modification of critical data. This vulnerability impacts data confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-87128

Oracle Hyperion Data Relationship Management Access Control Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated network attackers to compromise the system via HTTP, potentially leading to unauthorized access, creation, deletion, or modification of critical data. This is a concern because it impacts data integrity and confidentiality within the

CVE advisoryCRITICAL

CVE-2026-83462

Oracle Mobile Application Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Mobile Application Server, part of Oracle E-Business Suite, allows unauthenticated network attackers to potentially take over the server. This could impact confidentiality, integrity, and availability. Confirming its relevance and exposure in your environment is crucial to understandi

CVE advisoryCRITICAL

CVE-2026-83452

Oracle E-Business Suite Document Management Internal Operations Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Document Management and Collaboration within Oracle E-Business Suite, allowing unauthenticated attackers with network access to take over the system. This issue could impact the confidentiality, integrity, and availability of the product. Confirmation of the product's usage and

CVE advisoryCRITICAL

CVE-2026-83355

Oracle Enterprise Manager for Fusion Middleware Metrics Vulnerability Leads to Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Enterprise Manager for Fusion Middleware's Metrics component. Unauthenticated attackers with network access could exploit this to take over the management system. This could impact the confidentiality, integrity, and availability of the platform.

CVE advisoryCRITICAL

CVE-2026-83339

Oracle WebCenter Enterprise Capture Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture allows unauthenticated attackers with network access to compromise the product, potentially leading to a complete takeover. This impacts the confidentiality, integrity, and availability of the system. Given its network-accessible nature, Oracle WebCenter E

CVE advisoryCRITICAL

CVE-2026-83327

Oracle E-Business Suite Unauthenticated Takeover Vulnerability in Personalization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Applications Framework, a component of Oracle E-Business Suite, allows unauthenticated attackers with network access to compromise the framework. Successful exploitation could lead to a complete takeover, impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-83283

Oracle Business Intelligence Enterprise Edition Unauthenticated Network Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated network attackers to take over the system, impacting data confidentiality, integrity, and availability. Confirmation of exposure is crucial due to the potential for a full system compromise.

CVE advisoryCRITICAL

CVE-2026-83282

Oracle Business Intelligence Enterprise Edition Platform Security Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Business Intelligence Enterprise Edition that could allow a low-privileged attacker with network access to compromise the system and potentially impact other products. Successful exploitation could lead to a full takeover of the affected Oracle Business Intelligence Enterprise

CVE advisoryCRITICAL

CVE-2026-83268

Oracle BI Publisher High Privilege Network Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle BI Publisher, part of Oracle Analytics, could allow a highly privileged attacker with network access to take over the system and potentially affect other products. This issue is concerning because it may lead to a complete compromise of the BI Publisher application. Uncertainty remain

CVE advisoryCRITICAL

CVE-2026-83261

Oracle Product Lifecycle Analytics Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Product Lifecycle Analytics, allowing unauthenticated attackers with network access to completely take over the system. This could impact confidentiality, integrity, and availability. The reachability of this product via the network warrants attention to assess potential busine

CVE advisoryCRITICAL

CVE-2026-83260

Oracle Agile PLM Event Java PX Vulnerability Allows High Privileged Attacker Takeover

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Agile PLM could allow a high-privilege attacker with network access to take over the system, potentially impacting other products. This issue is easily exploitable and requires confirmation of the affected product version and its network reachability.

CVE advisoryCRITICAL

CVE-2026-83232

Oracle Data Integrator Console Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in Oracle Data Integrator allows network attackers to compromise the system, potentially leading to a complete takeover. This critical flaw impacts Oracle Fusion Middleware and is easily exploitable. Confirming the use of Oracle Data Integrator within your environment is essential to un

CVE advisoryCRITICAL

CVE-2026-83229

Oracle Siebel CRM Deployment Vulnerability Allows Takeover via Network Access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Deployment's Management Console allows a highly privileged attacker with network access via HTTP to potentially take over the system. This could impact additional products, leading to a complete compromise of the Siebel CRM Deployment.

CVE advisoryCRITICAL

CVE-2026-83202

Oracle Siebel CRM Server Infrastructure Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Siebel CRM Server Infrastructure enables unauthenticated attackers with network access to compromise deployments. This could result in unauthorized access to, or modification of, critical business data. The issue is exploitable via HTTP and impacts confidentiality and integrity.

CVE advisoryCRITICAL

CVE-2026-83201

Oracle Siebel CRM Deployment Server Infrastructure Vulnerability Allows Unauthorized Data Access.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Siebel CRM Server Infrastructure, affecting specific versions, allows unauthenticated attackers with network access to compromise the system. This could result in unauthorized access, modification, or deletion of critical data.

CVE advisoryCRITICAL

CVE-2026-83197

Oracle Siebel CRM Financial Accounts Vulnerability Allows Data Access and Denial of Service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Siebel CRM's Financial Accounts component allows unauthenticated network attackers to access critical data or cause denial of service. This issue is exploitable via HTTP and could expose sensitive financial information or disrupt services.

CVE advisoryCRITICAL

CVE-2026-83196

Oracle Siebel CRM Deployment Takeover Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Oracle Siebel CRM's Server Infrastructure, allowing a high-privilege attacker with network access to compromise the deployment. Successful exploitation could lead to a complete takeover of the affected system and potentially impact other products. The vulnerability has significant imp

CVE advisoryCRITICAL

CVE-2026-83154

Oracle Siebel CRM Open UI Unauthorized Data Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Siebel CRM's Open UI component allows unauthenticated network attackers to potentially access, modify, or delete critical data. Successful exploitation could lead to unauthorized actions on sensitive information, impacting data integrity and confidentiality. Understanding the reachability and

CVE advisoryCRITICAL

CVE-2026-83149

Oracle Application Testing Suite Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Application Testing Suite enables a low-privileged attacker with network access to compromise the application, potentially leading to unauthorized access or modification of sensitive data and partial denial of service. This issue could impact other products, making its reach and consequences w

CVE advisoryCRITICAL

CVE-2026-83107

Oracle Forms Services Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Forms, part of Oracle Fusion Middleware, could allow a highly privileged attacker with network access to compromise the application and potentially affect other integrated products. This could lead to a complete takeover of Oracle Forms, impacting confidentiality, integrity, and avail

CVE advisoryCRITICAL

CVE-2026-83105

Oracle Forms Services Privilege Escalation Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Oracle Forms, a component of Oracle Fusion Middleware, which may allow an unauthenticated attacker with network access to compromise the application. Successful exploitation could lead to a takeover of Oracle Forms and potentially impact additional products.

CVE advisoryCRITICAL

CVE-2026-83104

Oracle Forms Network Access Critical Data Disclosure and Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Forms that could allow an unauthenticated attacker with network access to gain unauthorized control over critical data. This could result in the creation, deletion, or modification of sensitive information, or allow complete access to all data managed by Oracle Forms, impacting

CVE advisoryCRITICAL

CVE-2026-83095

Oracle Forms Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Forms allows unauthenticated attackers with network access to potentially take over the system, impacting its confidentiality, integrity, and availability. This issue is relevant if Oracle Forms is exposed via HTTP.A critical vulnerability exists in Oracle Forms, a component of Oracle

CVE advisoryCRITICAL

CVE-2026-83094

Oracle Forms Services Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Forms allows unauthenticated attackers with network access to compromise the system, potentially leading to a complete takeover. This issue impacts Oracle Fusion Middleware's Forms Services component and could affect business application interfaces, making it crucial to assess its rel

CVE advisoryCRITICAL

CVE-2026-83066

Oracle Internet Directory Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Oracle Internet Directory, allowing unauthenticated attackers with network access to achieve a complete takeover of the service. This compromise can impact data confidentiality, integrity, and availability, and is therefore a significant concern for organizations using this technology

CVE advisoryCRITICAL

CVE-2026-83064

Oracle WebCenter Portal Runtime Tools Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal's Runtime Tools, allowing a highly privileged attacker with network access to achieve takeover of the portal and potentially impact other connected products, affecting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-83062

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Internet Directory's LDAP server could allow unauthenticated attackers with network access to take over the service. This could impact the confidentiality, integrity, and availability of directory information. It is important to determine if this technology is used within the environm

CVE advisoryCRITICAL

CVE-2026-83061

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Internet Directory's LDAP Server component allows unauthenticated attackers with network access to compromise the product. Successful exploitation could result in a takeover of the Oracle Internet Directory. This is a concern because Oracle Internet Directory is a central identity management s

CVE advisoryCRITICAL

CVE-2026-83060

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Internet Directory's LDAP Server allows unauthenticated network attackers to compromise the system. Successful exploitation could lead to a complete takeover of the directory, impacting confidentiality, integrity, and availability. This issue is relevant to organizations using Oracle

CVE advisoryCRITICAL

CVE-2026-83059

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle Internet Directory's LDAP Server component that allows an unauthenticated network attacker to achieve a complete takeover of the directory. This compromise can significantly impact other products that rely on Oracle Internet Directory for identity services, affecting confidenti

CVE advisoryCRITICAL

CVE-2026-83058

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the Oracle Internet Directory's LDAP server component, allowing a low-privileged attacker with network access to potentially compromise the entire directory. This takeover could significantly impact other connected products, affecting confidentiality, integrity, and availability. Orga

CVE advisoryCRITICAL

CVE-2026-83055

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Oracle Internet Directory's LDAP server allows a low-privileged attacker with network access to compromise the system. Successful exploitation could lead to a takeover of the directory service, potentially impacting other connected products.

CVE advisoryCRITICAL

CVE-2026-83054

Oracle Internet Directory LDAP Server Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Oracle Internet Directory's LDAP Server can be exploited by unauthenticated attackers with network access, potentially leading to a complete takeover of the directory. This impacts core identity and access management functions and could compromise confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-83042

Oracle Identity Manager Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Identity Manager allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover and impacting identity and access management functions. The ease of exploitation and the severity of potential impacts necessitate understanding the r

CVE advisoryCRITICAL

CVE-2026-83040

Oracle WebCenter Portal Unauthenticated Network Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal's Portlet Services component that could allow an unauthenticated attacker with network access to achieve full control of the affected portal, potentially impacting other products. This issue requires user interaction to be exploited.

CVE advisoryCRITICAL

CVE-2026-83039

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal, allowing a low-privileged attacker with network access via HTTP to potentially compromise the application and impact related products. This could lead to a complete takeover of Oracle WebCenter Portal, affecting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-83038

Oracle WebLogic Server Takeover Vulnerability Affects Multiple Versions.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebLogic Server's TopLink Integration component. A low-privileged attacker with network access via HTTP can exploit this to take over the server, potentially impacting other connected products. The vulnerability is easily exploitable and carries a CVSS score of 9.9.

CVE advisoryCRITICAL

CVE-2026-83037

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Sites, allowing unauthenticated attackers with network access to compromise the system, potentially leading to a complete takeover. This could impact the confidentiality, integrity, and availability of the affected Oracle WebCenter Sites.

CVE advisoryCRITICAL

CVE-2026-83036

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Sites allows unauthenticated attackers with network access to take over the system. This could result in a complete compromise of the content management platform, impacting confidentiality, integrity, and availability. It is important to determine if Oracle WebCenter Sites i

CVE advisoryCRITICAL

CVE-2026-83035

Oracle WebCenter Sites Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker with network access can compromise Oracle WebCenter Sites, potentially leading to a complete takeover of the system. This vulnerability impacts confidentiality, integrity, and availability, making it a critical concern for organizations using the affected product.

CVE advisoryCRITICAL

CVE-2026-83029

Oracle Managed File Transfer Critical Data Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Managed File Transfer could allow a low-privileged attacker with network access to modify or delete critical data and gain complete access to all accessible data. This issue may also significantly impact additional Oracle products.

CVE advisoryCRITICAL

CVE-2026-83021

Oracle WebLogic Server HTTP Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server's Web Container component allows unauthenticated attackers with network access to take over the server, potentially impacting other products. This issue affects the confidentiality, integrity, and availability of the affected system.

CVE advisoryCRITICAL

CVE-2026-83020

Oracle Platform Security for Java Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Platform Security for Java could allow unauthenticated attackers to gain complete control of the system via network access, potentially impacting other connected products. This affects Oracle Fusion Middleware, and exploitation could lead to a significant compromise of confidentiality

CVE advisoryCRITICAL

CVE-2026-83006

Oracle WebCenter Enterprise Capture High Privilege Network Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle WebCenter Enterprise Capture could allow a highly privileged attacker with network access to take over the application, potentially impacting other connected products. This issue is exploitable via HTTP.

CVE advisoryCRITICAL

CVE-2026-83001

Oracle Access Manager Authentication Engine Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Access Manager's Authentication Engine may allow a highly privileged attacker with network access to take over the system. This takeover could also impact other connected products, making it a significant security concern for identity and access management.

CVE advisoryCRITICAL

CVE-2026-83000

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows unauthenticated network attackers to achieve complete platform takeover via HTTP, impacting confidentiality, integrity, and availability. This issue should be a concern due to the platform's role in service integration.

CVE advisoryCRITICAL

CVE-2026-82999

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows a low-privileged attacker with network access to potentially take over the platform and impact other connected products. The issue, rated with a CVSS score of 9.9, could severely affect confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-82997

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows a low-privileged attacker with network access to compromise the platform, potentially impacting other products and leading to a full takeover. <tool_code print(google_search.search(queries=["Oracle Fusion Middleware Service Delivery

CVE advisoryCRITICAL

CVE-2026-82995

Oracle Platform Security for Java Takeover Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle Platform Security for Java, part of Oracle Fusion Middleware, allows unauthenticated network attackers to take over the system. This impacts confidentiality, integrity, and availability. Confirming the presence and network exposure of this component in your environment is important.A

CVE advisoryCRITICAL

CVE-2026-82994

Oracle Platform Security for Java LDAP Takeover Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Oracle Platform Security for Java, a component of Oracle Fusion Middleware, allows unauthenticated attackers with network access via LDAP to compromise the system, potentially leading to a full takeover. This impacts confidentiality, integrity, and availability. The main concern is confirmin

CVE advisoryCRITICAL

CVE-2026-73963

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal that allows an unauthenticated attacker with network access to potentially compromise the entire system. This flaw, affecting the Portlet Services component, could lead to a complete takeover of the affected Oracle WebCenter Portal. Organizations using this tec

CVE advisoryCRITICAL

CVE-2026-73962

Oracle Access Manager Authentication Engine Vulnerability Allows Unauthorized Data Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Access Manager's Authentication Engine that allows a low-privileged attacker with network access to compromise the system. This could lead to unauthorized access, modification, or deletion of critical data, and potentially impact other connected Oracle products.

CVE advisoryCRITICAL

CVE-2026-73957

Oracle WebCenter Portal Portlet Services Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized data modification or access. Although user interaction is required, successful exploitation may impact additional products. This threat poses a significa

CVE advisoryCRITICAL

CVE-2026-73953

Oracle WebCenter Portal Portlet Services Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal's Portlet Services, enabling unauthenticated attackers with network access to potentially achieve a complete takeover of the system. This issue could impact confidentiality, integrity, and availability, requiring assessment of its relevance and exposure within

CVE advisoryCRITICAL

CVE-2026-73952

Oracle WebCenter Portal Portlet Services Unauthorized Data Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Oracle WebCenter Portal's Portlet Services component. This issue allows an unauthenticated attacker with network access to potentially gain unauthorized access to, modify, or delete critical data. Organizations using this Oracle product should confirm its presence and assess potential

CVE advisoryCRITICAL

CVE-2026-73950

Oracle Access Manager Authentication Engine Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access to compromise the system, potentially leading to a full takeover and impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-73948

Oracle WebCenter Portal Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebCenter Portal allows a low-privileged attacker with network access to compromise the system and potentially impact other connected products. Successful exploitation could lead to a takeover of the portal, affecting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-73946

Oracle Access Manager Authentication Engine Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Access Manager's Authentication Engine. Attackers with high privileges and network access could exploit this to compromise the system, potentially affecting other products. This could lead to a full takeover of Oracle Access Manager.

CVE advisoryCRITICAL

CVE-2026-73945

Oracle Access Manager Authentication Engine Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Access Manager's Authentication Engine could allow a low-privileged attacker with network access to take over the system, potentially impacting other connected products. This issue is highly exploitable and poses a significant risk to confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-73944

Oracle Access Manager Authentication Engine Vulnerability Allows Unauthorized Data Access and Modification

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access to compromise the system, potentially leading to unauthorized access, creation, deletion, or modification of critical data. This issue is significant because Oracle Access Manager is a critical componen

CVE advisoryCRITICAL

CVE-2026-73940

Oracle Access Manager Authentication Engine Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Access Manager, a component of Oracle Fusion Middleware, allowing unauthenticated attackers with network access to potentially take over the system. This could impact confidentiality, integrity, and availability. Oracle Access Manager is an identity and access management soluti

CVE advisoryCRITICAL

CVE-2026-71163

Oracle Access Manager Authentication Engine Vulnerability Allows Unauthorized Data Access and Service Disruption

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with network access to compromise the system. This could lead to unauthorized access to critical data, modification of data, or a partial denial of service, potentially impacting Oracle Access Manager and other connected p

CVE advisoryCRITICAL

CVE-2026-71133

Oracle Access Manager Authentication Engine Vulnerability Leads to Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Oracle Access Manager's authentication engine, allowing unauthenticated network access to compromise the system. Successful exploitation could lead to a complete takeover of Oracle Access Manager, potentially impacting other connected products and affecting confidentiality, integrity,

CVE advisoryCRITICAL

CVE-2026-70913

Oracle Identity Manager Unauthenticated Network Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle Identity Manager allows unauthenticated attackers with network access to gain complete control of the system. This could impact the confidentiality, integrity, and availability of the identity management solution.

CVE advisoryCRITICAL

CVE-2026-70757

Oracle WebLogic Server Authentication Bypass Leads to Full Server Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers to gain complete control of the server over the network. Successful exploitation could lead to the compromise of all data and system functions managed by the affected server. This issue requires immediate attention to determine if your

CVE advisoryCRITICAL

CVE-2026-70756

Oracle WebLogic Server T3 IIOP Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated network attackers to compromise the server, potentially leading to a complete takeover. This issue, reachable via T3 and IIOP protocols, affects specific versions of the product. Understanding if your organization uses vulnerable versions and if

CVE advisoryCRITICAL

CVE-2026-70748

Oracle WebLogic Server Core Vulnerability Allows Full Server Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Oracle WebLogic Server allows unauthenticated network attackers to take over the server. This issue impacts confidentiality, integrity, and availability, and it is reachable via T3 and IIOP protocols, making it a significant concern for any environment using this technology.

CVE advisoryCRITICAL

CVE-2026-69204

Http4s Ember HTTP/1.1 Request Smuggling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in http4s allows attackers to smuggle requests by sending messages with both Transfer-Encoding and Content-Length headers, potentially bypassing access controls and poisoning caches. This issue affects the Ember HTTP/1.1 component when it disagrees with an intermediary on message framing.

CVE advisoryKnown Exploit

CVE-2026-58704

Android Cellular Modem Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A logic error in the cellular modem of Google Android devices could allow for privilege escalation with adjacent network access, bypassing permission checks without user interaction. This vulnerability poses a risk of unauthorized access and control to affected devices. <hr> I'm sorry, but I cannot fulfill this request

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-56960

Android Use-After-Free Logic Error Leads to Remote Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic error in the Android operating system can allow an attacker to remotely escalate privileges with no user interaction. This could lead to unauthorized access and control of affected devices if the vulnerable components are reachable.

CVE advisoryCRITICAL

CVE-2026-61667

DIRAC SQL Injection and Command Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the DIRAC distributed computing framework allows an authenticated user to execute commands by manipulating dataset names. This could expose credentials and system configurations, and alter log evidence. It is important to identify any DIRAC instances and assess their exposure.

CVE advisoryCRITICAL

CVE-2026-53459

Bambuddy Authentication Bypass via Resource Exhaustion Allows Unauthenticated Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in Bambuddy's authentication allows unauthenticated access to protected data by overwhelming a public endpoint. This resource exhaustion causes database access to fail, granting unauthorized entry to all system functions. The integrity and confidentiality of archived print job data are at risk.

CVE advisoryCRITICAL

CVE-2026-45579

DIRAC Request Management System Code Injection Leads to Full System Compromise.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the DIRAC distributed computing framework allows an authenticated user to execute arbitrary operating system commands. This occurs when a specially crafted attribute is passed to a function, causing it to evaluate as Python code. Exploitation could lead to the compromise of sensitive data, full syste

CVE advisoryCRITICAL

CVE-2026-12351

IBM MQ Unsafe JNDI Lookup Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM MQ software contains a critical vulnerability in its IVT application related to unsafe JNDI lookup processing, which may permit remote attackers to execute arbitrary code. This could affect system confidentiality, integrity, and availability if the vulnerability is reachable or relevant.

CVE advisoryCRITICAL

CVE-2026-11928

IBM Verify Identity Access Buffer Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical buffer overflow vulnerability exists in IBM Verify Identity Access. This flaw could allow an unauthenticated attacker to execute arbitrary code, potentially impacting system confidentiality, integrity, and availability. The primary concern is to determine if this technology is in use and exposed.

CVE advisoryCRITICAL

CVE-2026-11921

IBM Verify Identity Access Password Change Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Verify Identity Access containers may not correctly apply management password changes. This could allow an unauthenticated attacker to gain unauthorized access to identity and access management functions when the technology is network-exposed. Confirming the presence and exposure of IBM Verify Identity Access in yo

CVE advisoryCRITICAL

CVE-2026-89026

Issabel PBX Hard-Coded JWT Key Allows Remote Command Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in the Issabel Framework, a component of Issabel PBX software, due to a hard-coded JWT signing key. This allows unauthenticated remote attackers to forge valid tokens and execute arbitrary operating system commands via a specific API endpoint. This is concerning because Issabel PBX systems are of

CVE advisoryCRITICAL

CVE-2026-89022

BookStack Social Login Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

BookStack's social login feature has an authentication bypass vulnerability, allowing unauthenticated attackers to impersonate users. This occurs when a social provider is used with a shared driver ID namespace, bypassing normal credential checks. The risk is to user accounts and access if social login is enabled and c

CVE advisoryCRITICAL

CVE-2026-53710

MCP Context Forge Python Sandbox Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MCP Context Forge's Python sandbox server has a critical vulnerability allowing unauthenticated attackers to execute OS commands with server process privileges. This occurs when the `execute_code` tool is exposed via HTTP/SSE transport, enabling the bypassing of security checks. The issue affects the Python sandbox sub

CVE advisoryCRITICAL

CVE-2026-46488

motionEye Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

motionEye, a video surveillance interface, has a vulnerability allowing unauthenticated attackers to impersonate users if they know a username and hash. This could lead to unauthorized access, data manipulation, or exfiltration. Identifying and assessing motionEye instances is crucial for risk management.

CVE advisoryCRITICAL

CVE-2024-58385

Yonyou U8 CRM Unauthenticated SQL Injection with OS Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Yonyou U8 CRM has an unauthenticated SQL injection vulnerability in a configuration endpoint. Attackers can exploit this to execute arbitrary SQL commands, and potentially arbitrary operating system commands on certain Microsoft SQL Server configurations. This could expose system configuration data and allow unauthoriz

CVE advisoryCRITICAL

CVE-2023-54398

Yonyou U8 Cloud Unauthenticated Java Deserialization RCE via FileManageServlet.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Yonyou U8 Cloud has a vulnerability in its file management component that permits unauthenticated remote attackers to execute arbitrary operating system commands. This could lead to unauthorized system control if the affected component is reachable.

CVE advisoryCRITICAL

CVE-2026-91949

FreeRDP Protocol Negotiation Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A protocol negotiation bypass vulnerability in FreeRDP servers allows unauthenticated attackers to establish RDSTLS connections, bypassing server policies designed to prevent them. This could enable unauthorized remote desktop access to systems that provide remote access services.

CVE advisoryCRITICAL

CVE-2026-91932

Flowise Remote Code Execution via Unvalidated CWD Parameter.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A validation bypass vulnerability in Flowise allows authenticated attackers to achieve remote code execution by manipulating the `cwd` parameter within MCP server configurations. This bypasses path validation, enabling attackers to control the working directory and execute malicious code. This is relevant if Flowise is

CVE advisoryCRITICAL

CVE-2026-91931

Flowise Custom MCP Node RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in Flowise's Custom MCP node, allowing authenticated attackers to run arbitrary code on the server by providing malicious package names. This could lead to unauthorized control over the Flowise instance. Owners of Flowise applications and supporting teams should inv

CVE advisoryCRITICAL

CVE-2026-77972

Safeurl TOCTOU Race Condition Allows Unauthorized Network Access.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Time-of-check Time-of-use (TOCTOU) race condition in the safeurl library allows an attacker controlling DNS responses to bypass validation and reach internal network destinations. This could enable unauthorized network access if the library is used for URL validation.

CVE advisoryCRITICAL

CVE-2026-77866

Slab safeurl SSRF Vulnerability Allows Internal Network Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Server-Side Request Forgery vulnerability in the Slab safeurl library allows an attacker to bypass restrictions and reach internal network destinations by manipulating URL formats, as only IPv4 addresses are correctly checked against blocklists. This could expose internal systems if the library is used in an applicat

CVE advisoryCRITICAL

CVE-2024-14029

Tornado HTTP Request Smuggling via Transfer-Encoding

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Tornado web framework allows for HTTP request smuggling due to improper handling of duplicate `Transfer-Encoding: chunked` headers. When deployed behind proxies, this can enable attackers to bypass access controls, poison caches, or desynchronize connections. This issue is relevant as it can affe

CVE advisoryCRITICAL

CVE-2023-54397

Tornado HTTP Request Smuggling via Improper Content-Length Parsing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Tornado web framework due to improper parsing of Content-Length headers, allowing non-standard characters. Attackers can exploit this to bypass proxy validation and smuggle requests when Tornado is deployed behind certain proxies, potentially leading to unauthorized actions.

CVE advisoryCRITICAL

CVE-2026-88617

SmartAdmin Privilege Escalation via Authorization Flaw

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SmartAdmin contains a critical authorization flaw in its configuration query endpoint, enabling remote attackers to escalate privileges. This could impact data integrity and confidentiality if the affected system is reachable. It is important to confirm its presence and exposure within our environment.

CVE advisoryCRITICAL

CVE-2026-63696

Dell SmartFabric OS10 Download of Code Without Integrity Check Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Dell SmartFabric OS10 Software could permit a privileged remote attacker to execute arbitrary code by bypassing integrity checks on downloaded code. While direct internet exposure is unlikely for this network operating system, organizations should verify if affected systems are reachable and assess p

CVE advisoryCRITICAL

CVE-2026-63695

Dell SmartFabric OS10 Session Fixation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell SmartFabric OS10 software has a session fixation vulnerability that could allow an unauthenticated remote attacker to steal user sessions. This affects network management infrastructure, a critical component of enterprise operations. The main concern is confirming relevance and exposure within your environment.

CVE advisoryCRITICAL

CVE-2026-61549

Woodpecker CI/CD Service Account Privilege Escalation in Kubernetes Backend

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Woodpecker CI/CD allows authenticated users with repository push permissions to execute pipeline pods using arbitrary ServiceAccounts, potentially leading to sensitive data exfiltration or cluster takeover. This issue arises from insufficient authorization when handling Kubernetes backend options.

CVE advisoryCRITICAL

CVE-2026-59971

MySQL MCP Server Unauthenticated Database Access and File Modification

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in MySQL MCP Server allows unauthenticated network attackers to execute arbitrary SQL queries, potentially leading to disclosure, modification, or even code execution on the database server. This occurs when the SSE transport is enabled without proper security settings, making the service reach

CVE advisoryCRITICAL

CVE-2026-55158

Conflibot Command Injection Vulnerability Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Conflibot tool allows for arbitrary command execution when processing a pull request with a malicious branch name. This could lead to the exfiltration of secrets and tokens, or unauthorized code modifications. The primary concern is assessing the tool's use within development workflows and its po

CVE advisoryCRITICAL

CVE-2026-46495

OpenDJ JMX RMI Connector Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in OpenDJ's JMX RMI connector that could allow unauthenticated remote attackers to execute code. Exploitation depends on the JMX handler being enabled and reachable, and was demonstrated under specific Java and library versions. This impacts the directory service's integrity.

CVE advisoryCRITICAL

CVE-2026-39919

Ghostscript JPEG 2000 Output Adapter Heap Buffer Overflow.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Ghostscript contains a heap-based buffer overflow vulnerability in its JPEG 2000 output adapter. Attackers can exploit this by providing a crafted PDF with a malicious JPEG 2000 image, which could lead to memory corruption and potential code execution. It is important to confirm if this component is used and exposed wi

CVE advisoryCRITICAL

CVE-2026-91998

Casdoor Authorization Bypass Allows Unrestricted Cross-Organization User Administration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authorization bypass vulnerability in Casdoor allows attackers with any application's credentials to administer users across all organizations, potentially exposing sensitive data and enabling unauthorized account management. This affects identity and access management, posing a significant risk if the affec

CVE advisoryCRITICAL

CVE-2026-91995

Pig Authentication Bypass Vulnerability Leads to Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in the `pig` application's registration endpoint allows unauthenticated remote attackers to overwrite any account credentials, including administrative ones. This could result in full administrative control of the affected system.

CVE advisoryCRITICAL

CVE-2026-57148

PraisonAI Authentication Bypass Allows Impersonation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in PraisonAI's authentication service allows unauthenticated attackers to impersonate users or workspace owners by exploiting an insecure default signing key. This can lead to unauthorized access when the system is configured with default development settings. The issue is present in versions prior to 0

CVE advisoryCRITICAL

CVE-2026-57147

PraisonAI Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in PraisonAI's authentication service allows unauthenticated remote attackers to forge security tokens and impersonate users. This occurs when a default, predictable secret is used for token signing due to specific configuration settings, potentially granting unauthorized access to protected API routes.

CVE advisoryCRITICAL

CVE-2026-57141

PraisonAI Code Mode Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the PraisonAI multi-agent system allows unauthenticated attackers to execute arbitrary JavaScript, potentially granting them access to host process capabilities like file access, credential retrieval, and OS command execution. This issue stems from inadequate sanitization of model-generated

CVE advisoryCRITICAL

CVE-2026-57140

PraisonAI AgentOS Unauthenticated API Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

PraisonAI's AgentOS component has a critical vulnerability allowing unauthenticated remote access to agent names, roles, and instructions, and enabling the invocation of agents. This could expose tools, memory, external APIs, credentials, and workflow state. Confirm if your deployment is affected and assess potential e

CVE advisoryCRITICAL

CVE-2026-57138

PraisonAI codeMode Untrusted JavaScript Execution Leading to Host Access

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in PraisonAI's code execution feature allows untrusted JavaScript to bypass sandbox restrictions, potentially enabling attackers to read secrets, modify files, or execute commands on the host system. This issue impacts systems that rely on this feature for code execution.

CVE advisoryCRITICAL

CVE-2026-62379

OpenAM Remote Code Execution via Unsafe Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Open Access Management (OpenAM) has a critical vulnerability where an unauthenticated attacker can execute arbitrary code on the server. This is possible because the authentication endpoint accepts an XML element that names an arbitrary Java class, which the server loads and instantiates without validation, especially

CVE advisoryCRITICAL

CVE-2026-62263

OpenAM WebAuthn Deserialization Gadget Found

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Open Access Management could allow an unauthenticated attacker to execute arbitrary code by exploiting a deserialization flaw before authentication. This bypasses previous security fixes and could impact the integrity and availability of the access management solution.

CVE advisoryCRITICAL

CVE-2026-48717

OpenAM Authorization Code Interception Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

OpenAM, an access management solution, has a vulnerability where an attacker can redeem intercepted authorization codes without proper verification. This is possible if the realm-wide code verifier enforcement is disabled, even when a code challenge is present. Public clients are directly affected, potentially leading

CVE advisoryCRITICAL

CVE-2026-46619

OpenAM Authentication Bypass via LDAP Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Open Access Management (OpenAM) has a vulnerability where an unauthenticated remote attacker can bypass authentication by manipulating LDAP search filters in the MSISDN module. If this module is enabled and accessible, an attacker could gain unauthorized access to a normal authenticated session without a password, pote

CVE advisoryCRITICAL

CVE-2026-45052

OpenAM SOAP Receiver Unauthenticated Persistent Entry Writes

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in OpenAM's SOAP receiver allows unauthenticated remote requests to write persistent entries, bypassing access controls. This could lead to manipulated service-routing or security records, impacting authentication and resource access. Readers should verify if their OpenAM deployments are exposed and rel

CVE advisoryCRITICAL

CVE-2026-45051

OpenAM WebAuthn Deserialization Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Open Access Management's WebAuthn authentication can be exploited via unsafe deserialization if an attacker can control user attributes, potentially leading to code execution on the application server. This requires the WebAuthn flow to be reachable and controlled data to be pre-written to an attribute.

CVE advisoryCRITICAL

CVE-2026-90711

proxy-addr Trust Subnet Flaw Exposes Applications to IP Spoofing.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a Node.js module used to determine client IP addresses behind proxies. When configured with a specific malformed trust subnet, it may incorrectly trust all IPv4 addresses, allowing unauthenticated clients to spoof their origin IP. This can undermine IP-based access controls, rate limiting, and