NVD disclosure day

Published threat advisories for September 16, 2026

CVE advisoryCRITICAL

CVE-2026-92578

WWBN AVideo Authentication Bypass via Stored Password Hash

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WWBN AVideo has an authentication bypass vulnerability where stored password hashes can authenticate users. Attackers can gain unauthorized access by submitting a stolen password hash directly to login endpoints, bypassing verification. This impacts user account access and requires confirmation of the platform's releva

CVE advisoryCRITICAL

CVE-2026-92576

HKUDS nanobot WebFetchTool Server-Side Request Forgery Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in HKUDS nanobot's WebFetchTool allows attackers to access internal data and cloud metadata by tricking the bot into fetching specific addresses. The affected technology's relevance and reachability need to be confirmed to assess potential impact.

CVE advisoryCRITICAL

CVE-2026-61594

Djust WebSocket Authorization Bypass Allows Anonymous Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in djust's server-side rendering and WebSocket transport could allow unauthorized access to Django views, including administrative functions, by bypassing standard authorization checks over WebSocket connections. This could enable anonymous users to interact with sensitive data and functionality. The is

CVE advisoryCRITICAL

CVE-2026-92805

UVdesk Community Skeleton Unauthenticated Super Admin Creation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

UVdesk Community Skeleton's installation wizard lacks authentication, allowing unauthenticated attackers to create super administrator accounts and gain full instance control. This vulnerability is reachable via network requests to wizard endpoints, posing a significant risk to helpdesk systems.

CVE advisoryCRITICAL

CVE-2026-92787

Feast Authentication Bypass Via Unverified JWT Tokens

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in Feast allows unauthenticated attackers to bypass access controls by submitting an unverified JWT, potentially granting them unchecked read and write access to sensitive system data, including feature views, data sources, and permission policies.

CVE advisoryCRITICAL

CVE-2026-92785

Angel Kryo Deserialization RCE via RPC Endpoint.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Angel's master RPC endpoint has a deserialization vulnerability allowing unauthenticated attackers to send crafted serialized objects, potentially leading to arbitrary class instantiation or memory exhaustion. This impacts the integrity and availability of the machine learning platform. Understanding if your organizati

CVE advisoryCRITICAL

CVE-2026-92749

SafeLine Authentication Bypass via Weak Session Secret

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in SafeLine through version 9.4.1 allows unauthenticated remote attackers to reconstruct the management console's session-signing secret offline. If an attacker can estimate the installation timestamp, they can forge administrator session cookies to gain control of protected sites. This issue a

CVE advisoryKnown Exploit

CVE-2026-76460

Cisco ISE Authentication Bypass Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Cisco Identity Services Engine APIs allows unauthenticated, remote attackers to bypass authentication and gain unauthorized access to the web-based management interface. This is due to insufficient authentication controls on an API endpoint that can be exploited by sending a crafted request. You shou

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-75513

Marten SQL Injection via Unescaped String Literals

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Marten, a .NET transactional document and event store, has a vulnerability that allows SQL injection when runtime strings are not properly escaped in SQL literals. This can lead to authorization bypass and data exfiltration, and potentially data modification if Npgsql statements are batched with semicolons. While direc

CVE advisoryCRITICAL

CVE-2026-20332

Cisco ASA FTD FMC Improper Access Control Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

This advisory details improper access control vulnerabilities within Cisco Secure Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center software. If reachable, these flaws could allow unauthorized actions, potentially impacting system behavior, data confidentiality, and inte

CVE advisoryCRITICAL

CVE-2026-20284

Cisco ISE SXP REST API SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Cisco ISE's SXP REST API may allow an authenticated attacker to perform SQL injection attacks. This could lead to viewing or altering database information. In some cases, it could also cause a denial-of-service condition, preventing new devices from accessing the network.

CVE advisoryCRITICAL

CVE-2025-56563

Zenith Satellite Tracker SSRF Vulnerability Allows Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical Server-Side Request Forgery vulnerability in Zenith Satellite Tracker allows unauthenticated attackers to force the server to make arbitrary requests to internal networks or cloud services, potentially exposing sensitive data or enabling further attacks. Its relevance depends on the software's deployment and

CVE advisoryCRITICAL

CVE-2026-92808

Altium Enterprise Server UnifiedLogin SSRF Credentials Theft

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability in Altium Enterprise Server's UnifiedLogin service allows unauthenticated attackers to trick the server into sending requests to internal systems. This can expose server configuration and credentials, potentially leading to a full server compromise. Altium 365 cloud deploymen

CVE advisoryCRITICAL

CVE-2026-89082

HP Advance Privilege Escalation and Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

HP Advance software has vulnerabilities that could allow privilege escalation, remote code execution, or arbitrary file writes on the hosting server if reachable. This is a critical issue impacting server-side data and processes, potentially compromising print management services. The exact impact is uncertain as speci

CVE advisoryCRITICAL

CVE-2026-88592

kkFileView SSRF via Misvalidated URL Parameter.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

kkFileView is susceptible to Server-Side Request Forgery, where an attacker can trick the application into fetching unintended network resources by exploiting a URL parameter validation flaw. This could potentially expose sensitive information by echoing back the response body of the forged request.

CVE advisoryCRITICAL

CVE-2026-20341

Cisco FMC sftunnel Unsecured Deserialization Root Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco Secure FMC Software's inter-device communication protocol could allow an authenticated attacker to gain root privileges. This is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this by sending crafted remote procedure calls,

CVE advisoryCRITICAL

CVE-2026-20330

Cisco ASA FTD FMC Improper Neutralization Vulnerabilities

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Cisco security products are affected by improper neutralization vulnerabilities. These issues could allow for a significant compromise of confidentiality, integrity, and availability if exploited. Confirmation of product relevance and exposure within your environment is important.

CVE advisoryCRITICAL

CVE-2026-20329

Cisco ASA FTD FMC Improper Exception Handling Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

This vulnerability in Cisco security software relates to improper exception handling. If reachable, it could allow an attacker with low privileges to impact system confidentiality, integrity, and availability. Confirmation of affected products and exposure within your environment is necessary.

CVE advisoryCRITICAL

CVE-2026-20326

Cisco Nexus Dashboard Missing Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Cisco Nexus Dashboard where critical functions lack proper authentication. This could allow an attacker to perform unauthorized actions, potentially impacting network management and control. The relevance and exposure of this issue to your environment require confirmation.

CVE advisoryCRITICAL

CVE-2026-20325

Cisco Nexus Dashboard Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Cisco Nexus Dashboard has a vulnerability where improper handling of special characters in commands can allow an authenticated attacker to execute arbitrary commands. While typically managed internally, network-exposed management platforms could be reachable if misconfigured, potentially impacting system operations and

CVE advisoryCRITICAL

CVE-2026-20324

Cisco FMC sftunnel Command Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco Secure Firewall Management Center's sftunnel protocol allows authenticated users to write arbitrary files, potentially leading to root-level command execution. This could enable an attacker to compromise the affected device if the sftunnel communication is reachable or relevant.

CVE advisoryCRITICAL

CVE-2026-20322

Cisco Nexus Dashboard Improper Access Control Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Cisco Nexus Dashboard has an improper access control vulnerability that could allow a low-privileged authenticated user to gain unauthorized access and impact system integrity. This could affect confidentiality, integrity, and availability if exploited. Cisco has released a software hardening update to address this.

CVE advisoryCRITICAL

CVE-2026-20242

Cisco FMC External Database Access RCE Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco Secure Firewall Management Center's External Database Access feature allows an unauthenticated attacker to execute arbitrary commands as root on a device. This exploit requires the attacker to control a host already listed in the device's external database access configuration. If the managemen

CVE advisoryCRITICAL

CVE-2026-20237

Cisco ISE Improper Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Cisco Identity Services Engine and its Passive Identity Connector have vulnerabilities due to improper input validation, addressed by a software hardening release. An attacker could exploit these to impact confidentiality, integrity, and availability. Understanding system deployment and exposure is crucial for leadersh

CVE advisoryCRITICAL

CVE-2026-20211

Cisco ISE Command Execution via Insecure Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco Identity Services Engine could permit an authenticated attacker with high-privileged administrative credentials to execute arbitrary commands on the underlying operating system. This could result in user-level access, privilege escalation to root, or a denial-of-service condition, preventing un

CVE advisoryCRITICAL

CVE-2026-20194

Cisco ISE Incorrect Resource Transfer Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco Identity Services Engine and its Passive Identity Connector allows for incorrect resource transfer between security spheres. If reachable and exploited by an authenticated administrator, this could impact confidentiality, integrity, and availability. Confirming relevance within your environment

CVE advisoryCRITICAL

CVE-2026-20176

Cisco ISE Command Execution Vulnerability Allows Root Access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco ISE allows a high-privileged attacker to execute arbitrary commands on the operating system. Exploitation requires valid administrative credentials and a crafted HTTP request, potentially leading to system-level access and denial of service. This could disrupt network access for endpoints.

CVE advisoryCRITICAL

CVE-2026-20130

Cisco ISE Improper Neutralization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Cisco Identity Services Engine and ISE Passive Identity Connector due to improper neutralization of special elements (CWE-74). This could allow a remote attacker to compromise confidentiality, integrity, and availability of the affected systems. The relevance and exposure across the e

CVE advisoryCRITICAL

CVE-2026-91106

HP HPLIP Remote Code Execution and Privilege Escalation Vulnerabilities

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

HP's Linux Imaging and Printing software has vulnerabilities that may allow remote code execution or privilege escalation. The software's network exposure could lead to these impacts under certain conditions, affecting system integrity and confidentiality. Further assessment is needed to confirm exposure and determine

CVE advisoryCRITICAL

CVE-2026-91104

HP HPLIP Multiple Vulnerabilities

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

HP has remediated multiple vulnerabilities in its Linux Imaging and Printing software that could allow for remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification. These issues could be exploited by sending specially crafted data over a network.

CVE advisoryCRITICAL

CVE-2026-73456

Arista EOS gRPC Network Packet Sampling Interface Arbitrary Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated client can exploit a vulnerability in Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled to execute arbitrary code. This could grant an attacker full administrative control over the network switch, impacting network device integrity.

CVE advisoryCRITICAL

CVE-2026-68536

Apache MyFaces SSRF and LFI Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Apache MyFaces Core is vulnerable to Server-Side Request Forgery and Local File Inclusion. This flaw could allow an unauthenticated attacker to trick the server into making unintended requests or reading sensitive files. This is a critical vulnerability in a common web technology that could impact applications relying

CVE advisoryCRITICAL

CVE-2026-92720

Kubero Notifications API Unauthenticated Secret Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Kubero's notifications API allows unauthenticated access to webhook secrets and service URLs, enabling attackers to intercept pipeline events or disrupt alerting. Confirming if Kubero is used and exposed is crucial for protecting credentials and operational integrity.

CVE advisoryCRITICAL

CVE-2026-92717

Covenant SignalR Hub Missing Authentication Exposes Sensitive Data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Covenant framework allows unauthenticated access to its operator API, enabling attackers to retrieve sensitive information like credentials and binaries. This could lead to unauthorized control over the framework's operations if the technology is in use and accessible. Technical readers and secur

CVE advisoryCRITICAL

CVE-2026-76420

Apache JServ Protocol Connector Vulnerability Allows Remote Device Impersonation in Cisco Secure FMC Software

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Cisco Secure FMC Software's Apache JServ Protocol (AJP) connector allows an unauthenticated remote attacker to impersonate a peer device. This vulnerability, stemming from incorrect encryption parameter initialization, can lead to root command execution and full control of FMC REST APIs if the secure tunnel i

CVE advisoryCRITICAL

CVE-2026-20307

Cisco ISE Authenticated Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Cisco Identity Services Engine's web management interface that could allow an authenticated attacker with low-privileged credentials to execute arbitrary commands. This flaw stems from insecure deserialization of Java objects, which an attacker could exploit to run their own code on the device

CVE advisoryCRITICAL

CVE-2026-20306

Cisco ISE REST API Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco ISE and ISE-PIC REST APIs could allow an authenticated attacker with administrative credentials to inject commands, gaining root access and potentially causing denial of service, disrupting network access for unauthenticated endpoints.

CVE advisoryCRITICAL

CVE-2026-20234

Cisco Identity Services Engine and ISE-PIC Vulnerabilities Allow Unauthorized Access via Weak Credentials

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

json {"query": "Cisco Identity Services Engine and ISE-PIC vulnerabilities insufficiently protected credentials CWE-522"} ``````json {"tool_code": "print(google_search.search(queries=['Cisco Identity Services Engine ISE-PIC vulnerabilities insufficiently protected credentials CWE-522', 'CVE-2026-20234 Cisco ISE Passive

CVE advisoryCRITICAL

CVE-2026-90999

Sentry Seer Trust Boundary Violation Allows Unauthenticated Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Sentry Seer contains a trust-boundary violation allowing unauthenticated attackers to execute arbitrary code in a privileged environment by submitting fabricated telemetry. This bypasses authentication and could impact system integrity and availability. Confirmation of Sentry Seer exposure and its business criticality

CVE advisoryCRITICAL

CVE-2026-70416

Dell ObjectScale Deserialization Vulnerability Allows Remote Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell ObjectScale has a deserialization vulnerability that allows unauthenticated remote attackers to execute code. This could impact the integrity and availability of object storage systems. It is important to confirm if this technology is in use and potentially exposed.

CVE advisoryCRITICAL

CVE-2025-59953

LMDeploy RPC Server Deserialization Vulnerability Leads to Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A deserialization vulnerability exists in LMDeploy's RPC server that can lead to remote code execution if the server is reachable. This issue arises from unsanitized message deserialization, potentially allowing attackers to run arbitrary code. This could affect the integrity and availability of model serving infrastru

CVE advisoryCRITICAL

CVE-2026-77411

RabbitMQ Go Client Oversized Longstr Parsing Desynchronization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An oversized AMQP longstr field in the RabbitMQ Go client can cause parsing desynchronization, leading to disrupted connection integrity and availability if a malicious or compromised broker sends malformed data. This affects how applications communicate with message brokers. Confirmation of usage and exposure to untru

CVE advisoryCRITICAL

CVE-2026-77408

RabbitMQ amqp091-go Integer Overflow Leads to Metadata Corruption

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Go AMQP client library has a vulnerability where it mishandles oversized message metadata, leading to silent corruption. This can break request/reply correlation, routing, and downstream message processing. Applications using this library are at risk if they accept excessively long message property values.

CVE advisoryCRITICAL

CVE-2026-77405

RabbitMQ Go Client Negotiates Insecure TLS Versions

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the amqp091-go client library allows a network attacker to weaken transport security for AMQP messages and credentials by forcing negotiation of obsolete TLS protocol versions. This impacts applications using older builds of the client, potentially exposing sensitive data.

CVE advisoryCRITICAL

CVE-2026-91843

Unauthenticated Login Stack Overflow Leads to Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack overflow in an unauthenticated login process allows remote attackers to execute arbitrary code with root privileges. This critical vulnerability, which can be exploited over the network without prior authentication, poses a significant risk to affected systems and data.

CVE advisoryCRITICAL

CVE-2026-73172

Advantech EKI-1242EIMS OS Command Injection.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical OS command injection vulnerability exists in an Advantech industrial gateway management service, allowing unauthenticated remote attackers to execute arbitrary commands as root. This could impact device integrity and availability. Uncertainty remains regarding specific product versions and the potential for

CVE advisoryCRITICAL

CVE-2026-90048

Linux Kernel NTFS Slab Out-of-Bounds Write

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel's NTFS filesystem driver has a flaw allowing an out-of-bounds write when processing a crafted NTFS image, potentially leading to instability or compromise. This vulnerability requires a specially crafted, loop-mounted NTFS filesystem to be provided to the system.

CVE advisoryCRITICAL

CVE-2026-90042

Linux Kernel Ceph Filename Decryption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's Ceph filesystem client could lead to system instability by improperly decrypting filenames in memory. This issue occurs when messages are processed in specific memory regions, potentially causing unexpected behavior or crashes, particularly on non-x86 architectures.

CVE advisoryCRITICAL

CVE-2026-90038

Linux Kernel NFSD Use-After-Free in Export State Revocation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's NFS server could allow for unexpected behavior during export revocation. This could impact the stability of NFS services if an administrator revokes an export while a client is expiring. The exact impact is uncertain, but it is related to resource management within the kernel.

CVE advisoryCRITICAL

CVE-2026-90037

Linux kernel NFSD use-after-free vulnerability in client handling.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in the Linux kernel's NFS server (NFSD) component could allow an attacker to cause memory corruption during client handling. This race condition, exploitable over the network, may lead to system instability or compromise.

CVE advisoryCRITICAL

CVE-2026-90036

Linux Kernel NFSD Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's NFS server allows a use-after-free error during blocked lock reaping, potentially leading to system compromise if reachable. The issue stems from how client data is managed when locks are released concurrently with client expiration. This could impact system stability and availabil

CVE advisoryCRITICAL

CVE-2026-90011

Linux Kernel iSCSI Target Buffer Over-read Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Linux kernel's iSCSI target can be exploited by an unauthenticated initiator, potentially leading to memory corruption due to a missing terminator byte in login payloads. This could allow unauthorized access to adjacent memory. You should care if your environment utilizes iSCSI target services, a

CVE advisoryCRITICAL

CVE-2026-89990

Linux Kernel Ceph Use-After-Free Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's Ceph filesystem client could allow a use-after-free condition. This occurs when handling session OPEN requests, potentially leading to system instability or crashes. The flaw involves inspecting memory during concurrent session operations without proper locking.

CVE advisoryCRITICAL

CVE-2026-89972

Linux Kernel NVMe SRCU Grace Period Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's NVMe driver could allow a system crash or data corruption by improperly handling error conditions during namespace operations, leading to memory being freed while still in use. The fix adds necessary synchronization to prevent this race condition. Uncertainty exists regarding speci

CVE advisoryCRITICAL

CVE-2026-89970

Linux Kernel nvmet-auth Race Condition During Teardown

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition exists in the Linux kernel's NVMe target authentication that could lead to memory corruption during queue teardown if authentication work is still active. This could impact system stability and data integrity. The issue is relevant if NVMe target authentication is in use and reachable.A race condition

CVE advisoryCRITICAL

CVE-2026-89969

Linux Kernel NVMe-over-TCP Out-of-Bounds Write.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's NVMe-over-TCP component could allow an unauthenticated remote attacker to corrupt kernel memory. This occurs due to an out-of-bounds write when processing oversized network packets, potentially leading to system instability or compromise. Leaders should confirm if NVMe-over-TCP is

CVE advisoryCRITICAL

CVE-2026-89857

Linux Kernel qla2xxx Driver Ring Corruption Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's qla2xxx driver could lead to duplicated or dropped commands due to improper locking during NVMe LS reject operations, potentially corrupting the request ring state. This issue could impact data integrity and system stability if exploited.

CVE advisoryCRITICAL

CVE-2026-89846

Linux Kernel QLA2XXX Driver Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's qla2xxx SCSI driver could allow reading out-of-bounds memory. A malicious or buggy storage target could trigger this, potentially leaking sensitive data. Confirming the use of this driver in your environment is key to understanding potential exposure.

CVE advisoryCRITICAL

CVE-2026-76187

Apache Airflow Keycloak Provider Allows Unrestricted Client Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Apache Airflow Keycloak provider allows any confidential client's credentials in a shared Keycloak realm to authenticate to Airflow. This could enable an attacker to impersonate a service account, gaining unauthorized access to Airflow resources. The issue affects deployments that share a Keycloa

CVE advisoryCRITICAL

CVE-2026-76186

Apache Airflow Keycloak Provider Token Mismatch Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Apache Airflow Keycloak provider allows an attacker with a valid Airflow login to impersonate another user by pairing their session with a stolen Keycloak token, leading to unauthorized actions and data access. This affects Airflow versions 3.3 and later when using the Keycloak auth manager.

CVE advisoryCRITICAL

CVE-2026-73453

Arista EOS P4Runtime Arbitrary Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An unauthenticated client could execute arbitrary code on Arista EOS platforms if P4Runtime is enabled, leading to full administrative control of the switch. While this protocol is disabled by default, its reachability impacts critical network infrastructure. Uncertainty exists regarding exploitation and specific affec

CVE advisoryCRITICAL

CVE-2026-89788

Linux Kernel ksmbd Use-After-Free in SMB2 Tree Connect.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Linux kernel's ksmbd component could lead to system instability or crashes due to a use-after-free flaw during tree connection handling. If reachable via the network, this could impact availability or potentially allow unauthorized access. Identifying and confirming the network exposure of system

CVE advisoryCRITICAL

CVE-2026-89786

Linux ext4 Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's ext4 file system allows for an out-of-bounds read when processing directory entries. This flaw could permit unauthorized memory access or system instability if exploited through directory manipulation, but its reachability is uncertain.

CVE advisoryCRITICAL

CVE-2026-89783

Linux Kernel xfrm6 Out-of-Bounds Write Leads to Panic.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Linux kernel's IPsec networking could lead to an out-of-bounds write, potentially causing a system panic. Exploitation requires specific, complex network packet conditions related to security policy depth, limiting its broad impact but warranting confirmation of relevance and exposure for systems

CVE advisoryCRITICAL

CVE-2026-89779

Linux Kernel NTFS Heap Memory Leak Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's NTFS file system driver may allow a crafted image to leak heap memory. If an NTFS image is mounted, the driver's handling of extended attributes can be exploited to copy data beyond allocated buffers, potentially revealing sensitive kernel memory. This could be relevant for systems

CVE advisoryCRITICAL

CVE-2026-86462

Apache Airflow FAB Provider Password Reset Flaw Allows Session Hijacking.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Apache Airflow's FAB provider where changing a user's password does not invalidate existing sessions. This allows an attacker with a stolen session cookie to maintain access to a user's account even after a password reset. This impacts deployments using the FAB auth manager with database-backe

CVE advisoryCRITICAL

CVE-2026-82311

Apache Airflow FAB Session Invalidation Flaw Allows Persistent Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Apache Airflow FAB provider allows an attacker with a stolen session cookie to maintain access to a user's account even after a password reset. This occurs because the system does not properly invalidate existing database-backed sessions when a password is changed, despite documented behavior. Th

CVE advisoryCRITICAL

CVE-2026-81642

NLnet Labs Unbound DNSSEC Digest Buffer Overflow Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in NLnet Labs Unbound's DNSSEC validator may allow remote code execution or denial of service due to a buffer overflow when processing DNSKEY records. An attacker could exploit this by controlling a malicious zone and querying a vulnerable Unbound resolver. The potential for remote code executi

CVE advisoryCRITICAL

CVE-2026-73461

EOS gRPC Authorization Bypass on OpenConfig

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

On affected network platforms, an issue exists with AAA-based gRPC authorization for OpenConfig. Authenticated users making gRPC requests to OpenConfig may inadvertently use an incorrect privilege level, leading to improper authorization. This vulnerability does not affect non-gRPC OpenConfig requests. The primary conc

CVE advisoryCRITICAL

CVE-2026-27565

IODD File Upload Allows Root Shell Script Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can upload a malicious file to execute a persistent shell script with root privileges, potentially compromising system integrity and availability. The vulnerability's network exploitability and the persistence of the script post-reboot are key concerns.

CVE advisoryCRITICAL

CVE-2026-27546

Authentication Bypass in _account_log Allows Unauthenticated Admin Login

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can bypass login controls in a specific function to gain administrator access. This could potentially lead to unauthorized administrative control of system functions. Confirming system reachability and criticality is crucial for understanding potential exposure.

CVE advisoryCRITICAL

CVE-2026-73447

Arista EOS gNSI and Bootz Privilege Escalation and Command Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Arista EOS allows a privileged attacker to escalate privileges and execute arbitrary commands with root privileges via the gRPC Network Security Interface (gNSI) Certz or Bootz services, potentially leading to full device compromise. While authenticated access is required, successful exploit

CVE advisoryCRITICAL

CVE-2026-14349

TrueBooker WordPress Plugin Authorization Bypass Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The TrueBooker WordPress plugin contains an authorization bypass vulnerability that allows unauthenticated attackers to modify user email addresses, potentially leading to account takeovers through password resets. This issue affects all versions up to and including 1.2.3.

CVE advisoryCRITICAL

CVE-2026-12793

JetFormBuilder Privilege Escalation Allows Unauthenticated Administrator Creation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the JetFormBuilder WordPress plugin allows unauthenticated attackers to escalate privileges by creating new administrator accounts. This occurs because the plugin does not validate form IDs before processing form data, potentially enabling manipulation of server-side callbacks. Teams managin

CVE advisoryCRITICAL

CVE-2026-15640

Secret Server SAML IdP Response Impersonation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Secret Server allows an attacker to impersonate another user by exploiting a valid SAML Identity Provider response under specific conditions. This could lead to unauthorized access to sensitive information and system data. It is important to determine if your environment uses this technology and if i

CVE advisoryCRITICAL

CVE-2026-15639

Cross-Site Scripting Vulnerability via Malicious Link

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists where a malicious link, if clicked by a user, could cause their browser to execute attacker-supplied JavaScript. This could potentially lead to the compromise of user sessions or sensitive information. The relevance and exposure of this client-side threat to the environment need to be confirmed.