NVD disclosure day

Published threat advisories for September 17, 2026

CVE advisoryCRITICAL

CVE-2026-87701

Azure Cosmos DB Privilege Escalation via Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Azure Cosmos DB has an improper output neutralization vulnerability that allows an authorized attacker with network access to elevate privileges. This could impact the confidentiality and integrity of data within the service. Confirmation of affected deployments is needed.

CVE advisoryCRITICAL

CVE-2026-85889

Azure AI Foundry Missing Authentication Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Azure AI Foundry allows unauthenticated attackers to elevate privileges over a network. This could lead to unauthorized access and control. It is important to confirm if this technology is deployed and reachable within the environment.

CVE advisoryHIGH

CVE-2026-85885

M365 Copilot Command Injection Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A command injection vulnerability in M365 Copilot may allow an attacker to elevate privileges over a network. This could result in unauthorized command execution, impacting confidentiality, integrity, and availability. The relevance depends on how M365 Copilot is deployed and accessed within your environment.

CVE advisoryHIGH

CVE-2026-77903

Microsoft Dataverse Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. This technology is often used for internet-facing applications, increasing the potential for exposure. The main concern is to determine if your organization uses this Microsoft product and

CVE advisoryCRITICAL

CVE-2026-70009

Azure Arc Path Traversal Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthorized attacker can exploit a path traversal vulnerability in Azure Arc to elevate privileges over a network, potentially granting them unauthorized access and control. This issue requires attention to understand its relevance and potential exposure within your environment.

CVE advisoryCRITICAL

CVE-2026-69865

Microsoft Azure Container Registry Authorization Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization bypass vulnerability exists in Microsoft Azure Container Registry, allowing an unauthorized attacker to gain elevated privileges over a network. This could potentially compromise the confidentiality and integrity of container images stored in the registry.

CVE advisoryCRITICAL

CVE-2026-69399

Azure Arc Elevation of Privilege Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Azure Arc could allow an unauthenticated attacker to gain elevated privileges. This means an attacker could potentially access and control sensitive data or perform unauthorized actions on systems managed by Azure Arc when deployed in a network-accessible configuration.

CVE advisoryCRITICAL

CVE-2026-76949

Ash Authentication Bypass by Remember-Me Cookie Spoofing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in the `ash_authentication` library that allows an attacker to spoof a victim's session by planting a remember-me cookie. This could lead to an attacker gaining unauthorized access to a victim's account and data. This is a concern for systems utilizing this library, as it c

CVE advisoryCRITICAL

CVE-2026-54767

WeGIA Unauthenticated Table Truncation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the WeGIA web manager allows an unauthenticated remote attacker to permanently delete member and contributor records by exploiting an endpoint that checks against a hardcoded value. This could result in the loss of critical data if the affected tables exist and the database account has truncation pri

CVE advisoryCRITICAL

CVE-2026-54734

Prebid Server Java Bidder Adapter Request Forgery Allows Network Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Prebid Server Java contains a vulnerability where user-supplied parameters can be inserted into request URLs without proper validation. This could allow a malicious actor to cause the server to send HTTP requests to unintended internal or sensitive network destinations using the server's network access.

CVE advisoryCRITICAL

CVE-2026-54670

WeGIA Contribution Request Dispatcher Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the WeGIA web manager allows unauthenticated remote attackers to access sensitive donation records and trigger financial operations. Attackers may also disclose source code and credentials by manipulating file inclusion. This affects charitable institutions using the software.

CVE advisoryCRITICAL

CVE-2026-93393

MongoDB C Driver TLS Heap Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-based buffer overflow exists in the MongoDB C Driver when using the Windows TLS backend, allowing a remote attacker to corrupt memory or crash client applications by sending specially crafted encrypted traffic. This vulnerability occurs before application authentication and could lead to memory corruption or dis

CVE advisoryCRITICAL

CVE-2026-93372

Chrome for Android WebGL Buffer Overflow Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical buffer overflow vulnerability exists in Google Chrome's WebGL component on Android. Remote attackers can exploit this by directing users to a malicious HTML page, potentially enabling arbitrary code execution outside the sandbox. This could impact device confidentiality, integrity, and availability, warranti

CVE advisoryCRITICAL

CVE-2026-54501

Browsertrix Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in Browsertrix, a web archiving service, allowing unauthorized arbitrary operating-system command execution via a crafted Git URL when validating custom behaviors. This could lead to the exposure, modification, or deletion of sensitive application data, archived items,

CVE advisoryCRITICAL

CVE-2026-54460

OpenReception Appointment Booking Software Credential Takeover Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can exploit a vulnerability in OpenReception's appointment booking software to gain tenant administrative privileges. This could lead to the modification or deletion of tenant resources, potentially causing data loss and service disruption. The primary concern is confirming relevance and exp

CVE advisoryCRITICAL

CVE-2026-54237

Wavelog Configuration File Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Wavelog, amateur radio logging software, has a critical vulnerability allowing remote attackers to write to configuration files, leading to arbitrary code execution on the server. This issue arises because certain installation and interface files are exposed without proper permission checks after the software is instal

CVE advisoryCRITICAL

CVE-2026-45143

Chamilo LMS Message Content Cross-Site Scripting Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Chamilo LMS where crafted messages sent by authenticated low-privilege users can execute HTML in an administrator's browser, potentially exposing session credentials or enabling unauthorized actions. This issue affects the learning management system's private messaging functionality when messa

CVE advisoryCRITICAL

CVE-2026-45140

Chamilo LMS Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Chamilo LMS, an open-source learning management system, has a critical vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code on the server. The specific details of how this could be exploited are not identified, but such a flaw could lead to a server compromise. This issue is relev

CVE advisoryCRITICAL

CVE-2026-92943

AWS IoT SDK Python Certificate Host Mismatch Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the AWS IoT Device SDK for Python allows an adversary-in-the-middle to impersonate the AWS IoT Core endpoint and manipulate device communications. This occurs due to improper certificate validation, potentially enabling unauthorized access to device telemetry and injection of malicious messages. Read

CVE advisoryCRITICAL

CVE-2026-54752

NetBox Device Type Library Pickle Deserialization Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the NetBox Device Type Library's testing process allows for arbitrary code execution when processing community-submitted definitions. This could impact the integrity and availability of resources within the development or testing environments where these tests are run. The main concern at this time i

CVE advisoryCRITICAL

CVE-2026-54627

SAIL Library Heap Buffer Overflow Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The SAIL image loading library has a vulnerability that can be triggered by processing a specially crafted image file. This flaw could lead to memory corruption, a crash, or even arbitrary code execution if the library is used in an application that loads such a file. The impact depends on whether applications within y

CVE advisoryCRITICAL

CVE-2026-54626

SAIL TGA Image Handling Heap Buffer Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The SAIL image loading library has a vulnerability in its TGA file processing that could allow a crafted image to cause heap corruption or code execution. This occurs due to a mismatch in buffer allocation and data derivation when processing specific TGA file types. The risk is associated with the reachability of the l

CVE advisoryCRITICAL

CVE-2026-54618

Obsidian Web MCP Authorization and Token Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Obsidian Web MCP, a secure remote server for Obsidian vaults, has a vulnerability that allows unauthenticated remote attackers to access and manipulate vault data by bypassing login, consent, and session checks. If reachable, this could result in unauthorized reading, writing, searching, listing, moving, and deleting o

CVE advisoryCRITICAL

CVE-2026-54617

GravitLauncher File Server Path Traversal Leads to Credential Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote actor can exploit a path traversal vulnerability in GravitLauncher's file server to read sensitive files. This could expose signing keys, authentication tokens, and database credentials, enabling forged administrative access and authentication bypass.

CVE advisoryCRITICAL

CVE-2026-47252

Anyquery Command Execution Via Malicious URLs

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Authenticated users with INSERT or UPDATE access to Anyquery on macOS may execute arbitrary commands by providing a crafted URL to browser plugins. This vulnerability allows for script injection through the interpolation of controlled URLs into AppleScript.

CVE advisoryCRITICAL

CVE-2026-54053

Many Notes Vault Import Path Traversal Allows Arbitrary File Write and Stored XSS

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in a note-taking web application allows authenticated users to write arbitrary files to other users' vaults, potentially leading to stored cross-site scripting when a victim accesses their vault. This issue impacts the application's ZIP vault import feature.

CVE advisoryCRITICAL

CVE-2026-92489

Linux Kernel xfrm skb Double-Free Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's XFRM subsystem could lead to a double-free memory condition during packet processing, potentially causing system instability. This issue arises from incorrect memory handling when netfilter drops a packet. Its relevance depends on whether the affected kernel functions are utilized

CVE advisoryCRITICAL

CVE-2026-90413

Linux Kernel iSER Login PDU Handling Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's iSER component may allow an attacker to read beyond allocated memory buffers, potentially causing system instability or information disclosure. This issue arises from how login PDUs are processed, where a declared data length may exceed the actual received data. The impact depends

CVE advisoryCRITICAL

CVE-2026-90230

Linux Kernel NVMe Target Heap Out-of-Bounds Read

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap out-of-bounds read vulnerability exists in the Linux kernel's NVMe target authentication negotiation. This could allow a malicious host to read beyond allocated memory by sending a crafted request with unvalidated transfer lengths or identifiers. The issue impacts systems using this authentication mechanism.

CVE advisoryCRITICAL

CVE-2026-90173

Linux Kernel SMBdirect Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMBdirect component can lead to a use-after-free error when late network completions occur after completion queues are freed, potentially causing system instability or crashes. This low-level kernel issue requires verification of SMBdirect and RDMA usage and exposure to determine r

CVE advisoryCRITICAL

CVE-2026-90151

Linux Kernel NFSv4 Callback IDR Entry Removal Failure Leads to Stale Pointer

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's NFSv4 client can leave a stale pointer if client setup fails, potentially leading to a use-after-free condition. This occurs due to improper removal of a callback identifier during error handling, which could impact system stability or integrity if a callback lookup encounters the

CVE advisoryCRITICAL

CVE-2026-90110

Linux Kernel inetpeer Rate Limiting Bypass Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's network peer management could allow an attacker to bypass rate limits and infer open UDP ports. The issue stems from predictable internal data structures that attackers could exploit to manipulate system behavior and reset rate-limiting token buckets. This could lead to information

CVE advisoryCRITICAL

CVE-2026-91039

Authentication Bypass in ash_authentication Dynamic OIDC Strategy.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in ash_authentication's dynamic OIDC strategy could allow an attacker to impersonate local users by spoofing an identity provider connection. This happens because the system fails to properly isolate user identities across different connections. This could lead to unauthorized acc

CVE advisoryCRITICAL

CVE-2026-86863

pgAdmin 4 Webserver Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in pgAdmin 4's webserver authentication allows unauthenticated users to bypass access controls by supplying a crafted HTTP header. This could permit an attacker to impersonate any username, including administrators, without a password. Organizations using pgAdmin 4 with the 'webserver' authentication so

CVE advisoryCRITICAL

CVE-2026-76834

b2evolution CMS Object Injection via Negative Integer Array Key

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in b2evolution CMS allows unauthenticated attackers to execute arbitrary code. By submitting crafted serialized PHP objects, attackers can bypass validation and instantiate arbitrary PHP objects, potentially leading to code execution. This issue is relevant to organizations using affected versi

CVE advisoryCRITICAL

CVE-2026-88952

Ash Authentication Improper Authentication Allows Account Takeover Via OAuth2 Linking.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper authentication vulnerability in AshAuthentication allows an attacker to impersonate another user by linking a verified OAuth2 identity to an incorrect account. This could lead to unauthorized access to user accounts and associated data. The issue may also overwrite the legitimate user's email, redirecting a

CVE advisoryCRITICAL

CVE-2026-79752

CakePHP SQL Injection Vulnerability in FunctionsBuilder

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the CakePHP framework allows SQL injection through specific functions if untrusted input is not properly escaped. This could impact data confidentiality, integrity, and availability, depending on database privileges. Readers should determine if their applications use the affected CakePHP components a

CVE advisoryCRITICAL

CVE-2026-63472

Vendure Authentication Bypass Allows Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Vendure's external authentication service could allow an attacker to bind an external identity to a victim's existing account if email ownership is not verified. This could expose customer data and enable account changes or orders as the victim. The issue affects deployments with custom external auth

CVE advisoryCRITICAL

CVE-2026-92960

vm2 Sandbox Bypass Allows DNS Hijacking and Host Identity Exposure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 sandboxing library has a vulnerability that allows code within the sandbox to access host system information and manipulate DNS resolution. This could enable an attacker to hijack DNS queries globally, redirecting traffic through a resolver they control. Organizations should identify all instances of vm2 and as

CVE advisoryCRITICAL

CVE-2026-92957

vm2 NodeVM node prefix bypass allows code execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 sandboxing library has a vulnerability where it does not correctly normalize `node:`-prefixed module specifiers in its security policies. This flaw allows untrusted code running within the sandbox to bypass restrictions and gain access to sensitive Node.js built-in modules, potentially enabling arbitrary host c

CVE advisoryCRITICAL

CVE-2026-92956

vm2 Sandbox Escape via WebAssembly Compromises Node.js Host Capabilities

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the vm2 sandbox library, allowing code to escape and access host Node.js capabilities. This occurs when using specific WebAssembly functions, bypassing prior security fixes. The issue is reachable without special configurations and could grant attackers unauthorized access to host sys

CVE advisoryCRITICAL

CVE-2026-92955

vm2 Sandbox Escape via NodeVM console

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A sandbox escape vulnerability in the vm2 Node.js library allows attackers to execute code with process-level permissions, bypassing security restrictions. This could impact the host system when the library is used to execute untrusted code. It is important to verify if this library is in use within your environment.

CVE advisoryCRITICAL

CVE-2026-92954

vm2 Sandbox Unhandled Promise Rejection Denial of Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 sandbox library allows untrusted JavaScript code to trigger unhandled promise rejections, potentially crashing the Node.js host process. This could lead to a denial of service for applications using the library. The issue is a known but incomplete fix for a previous vulnerability and is resol

CVE advisoryCRITICAL

CVE-2026-92953

vm2 Prototype Pollution Allows Host Modification

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 JavaScript sandbox library allows attackers to mutate host data structures like TypedArray and ArrayBuffer prototypes. This could lead to unexpected behavior when host-created typed arrays are observed after sandbox execution. Confirming if your environment uses this library is crucial for un

CVE advisoryCRITICAL

CVE-2026-92951

vm2 Module Allowlist Bypass via Substring Matching

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 sandboxing library allows unauthorized execution of host packages by bypassing allowlist checks through non-exact substring matching. This could lead to unintended code execution if the affected technology is reachable. Readers should verify if vm2 is used in their systems and assess its conf

CVE advisoryCRITICAL

CVE-2026-92948

vm2 NodeVM Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the vm2 sandboxing library allows an attacker to bypass sandbox restrictions on Node.js 24 and newer. If an application explicitly allows the `node:test` module within the sandbox, an attacker could execute arbitrary JavaScript code on the host system. This requires a specific configuration and limit

CVE advisoryCRITICAL

CVE-2026-92947

vm2 Sandbox Memory Disclosure Via Shared Buffer Pool

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 sandbox library has a critical vulnerability that allows sandboxed code to access and potentially modify host memory via Node.js's shared Buffer pool, risking sensitive data exposure and denial-of-service. The relevance of this issue depends on whether the affected library is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-92946

vm2 Remote Code Execution Vulnerability with Require External Enabled

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A remote code execution vulnerability exists in the vm2 JavaScript sandbox library, allowing attackers to run arbitrary host OS commands. This could happen if the `require.external` feature is enabled without sufficient restrictions in applications that process untrusted code. The risk is considered possible due to pot

CVE advisoryCRITICAL

CVE-2026-92944

vm2 Sandbox Escape via Stale Promise Protector in Node.js

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical sandbox escape vulnerability exists in the vm2 library for Node.js, allowing attackers to execute arbitrary code on the host system by bypassing Promise protections. This impacts applications using vm2 to process untrusted code and warrants immediate attention to confirm usage and exposure.

CVE advisoryCRITICAL

CVE-2026-92941

vm2 TLS Trust Store Manipulation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the vm2 library allows attackers to tamper with TLS certificate authorities, potentially leading to Node.js applications trusting fraudulent security credentials. This could impact secure communications by enabling the acceptance of attacker-controlled certificates by host HTTPS clients. It is uncert

CVE advisoryCRITICAL

CVE-2026-92940

vm2 NodeVM Host Agent Information Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 JavaScript sandbox library has a vulnerability where configured sandboxed code can access the host's `https.globalAgent`. This could allow sandboxed code to intercept sensitive HTTPS request details, including authorization headers and response bodies, and issue authenticated requests. The issue is fixed in ver

CVE advisoryCRITICAL

CVE-2026-92939

vm2 Sandbox Escape via Crypto Module

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The vm2 library has a vulnerability that can allow code running within its sandbox to execute arbitrary native code on the host system. This happens when the Node.js crypto module is accessible and specifically when the `crypto.setEngine()` function is called with a path to a malicious library. This could lead to a san

CVE advisoryCRITICAL

CVE-2026-92938

vm2 Node.js SQLite Module Allows Native Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

The vm2 sandboxing library has a critical vulnerability that allows code within a Node.js sandbox to execute arbitrary native code on the host system. This occurs when the `node:sqlite` module is accessible, enabling a malicious plugin to load and execute untrusted native libraries, thereby bypassing sandbox restrictio

CVE advisoryCRITICAL

CVE-2026-92937

vm2 Sandbox Escape Via Promise Indirection Allows Remote Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in the vm2 library could allow sandboxed JavaScript code to escape and execute commands on the host Node.js process, especially if host-realm Promises are exposed. This could lead to arbitrary code execution if an attacker can manipulate Promise rejections through indirect calls, bypassing secu

CVE advisoryCRITICAL

CVE-2026-92935

vm2 Sandbox Escape via Improper `require` Handling

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 Node.js sandbox has a vulnerability where an improperly handled `require` option can allow an attacker to escape the sandbox and execute arbitrary commands with the host process's privileges. This requires specific configuration of the NodeVM, including nesting enabled and a `require` option structured as an ar

CVE advisoryCRITICAL

CVE-2026-92934

vm2 Sandbox Escape Leads to Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the vm2 sandboxing library could allow attackers to escape the sandbox and execute arbitrary code. This could lead to the disclosure of process information if the vulnerable component is reachable and exploited. Readers should verify if vm2 is used and exposed within their environment.

CVE advisoryCRITICAL

CVE-2026-86533

Ash Authentication Session Expiration Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in session management for authentication libraries could allow a revoked session to remain active, potentially enabling unauthorized access. This issue affects systems that use the vulnerable components, and the primary concern is verifying relevance and potential exposure. The main risk is that a sessi

CVE advisoryCRITICAL

CVE-2026-85500

AshAuthentication Bypass Allows Unconfirmed User Session

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in `ash_authentication` allows unconfirmed users to obtain a session by circumventing mandatory email confirmation. This occurs due to inconsistent checking of the confirmation attribute, particularly when API layers invoke actions directly or when the attribute is not loaded or i

CVE advisoryCRITICAL

CVE-2026-82761

AshAuthentication Magic Link Replay Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A Time-of-check Time-of-use (TOCTOU) race condition in AshAuthentication allows an attacker with a leaked magic link to replay its single-use token and authenticate as the target user. This occurs because the system checks the token's validity and then consumes it in separate steps, creating a window where concurrent r

CVE advisoryCRITICAL

CVE-2026-62108

Headless Single Sign-On Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical unauthenticated broken authentication vulnerability affects a Single Sign-On component, potentially allowing attackers to bypass login controls via network requests. This could lead to unauthorized access, though the specific impact on integrated systems is uncertain without further assessment.

CVE advisoryCRITICAL

CVE-2026-62104

Migratico Lite Unauthenticated Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in Migratico Lite, allowing unauthenticated attackers to execute arbitrary code over the network. This could lead to system compromise, data modification, or service disruption. The presence and accessibility of this technology within our environment need immediate

CVE advisoryCRITICAL

CVE-2026-62101

EduAdmin Booking Unauthenticated Broken Authentication Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated broken authentication vulnerability exists in EduAdmin Booking, potentially allowing unauthorized access to administrative functions and sensitive data. This issue could impact systems that handle bookings and scheduling. It is important to confirm if this technology is present and exposed within the

CVE advisoryCRITICAL

CVE-2026-92913

AVideo Account Takeover via Weak Activation Codes.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo uses a weak random number generator for account activation and login codes, allowing unauthenticated attackers to guess valid codes via an exposed API. Successful guesses grant account takeover by providing the account's email and a year-long bypass credential.

CVE advisoryCRITICAL

CVE-2026-92860

rcourtman Pulse Quick Security Setup Improper Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in rcourtman Pulse's Quick Security Setup Handler allows improper input validation of the 'Username' argument. This flaw, remotely exploitable with high privileges, could impact system data and service behavior. Understanding its relevance and exposure is key to assessing potential business impact.

CVE advisoryCRITICAL

CVE-2026-90823

FatPipe MPVPN Buffer Overflow Allows Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack-based buffer overflow vulnerability exists in FatPipe MPVPN, WARP, and IPVPN appliances. An unauthenticated remote attacker could exploit this flaw via the management interface, if enabled, to potentially execute arbitrary code as root. This could lead to unauthorized control over network traffic.

CVE advisoryCRITICAL

CVE-2026-90822

FatPipe OS Command Injection in xtremed Daemon

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An OS command injection vulnerability exists in FatPipe appliances running an older firmware version within the xtremed daemon. If the management interface is enabled, an unauthenticated remote attacker could execute arbitrary commands as root, potentially impacting system integrity. Confirmation is needed to determine

CVE advisoryCRITICAL

CVE-2026-81478

Dell OpenManage Server Administrator Hard-coded Key Vulnerability Allows Unauthorized Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Dell OpenManage Server Administrator has a Use of Hard-coded Cryptographic Key vulnerability that could allow unauthenticated remote attackers to gain unauthorized access. This is a critical issue because the flaw enables unauthorized access with network reachability.

CVE advisoryCRITICAL

CVE-2026-88795

WordPress wpShopGermany Plugin Remote Code Execution Via Insecure API Token Generation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin's insecure API token generation allows unauthenticated attackers to predict tokens and write arbitrary files, potentially leading to remote code execution. This vulnerability is accessible over the network and could affect any environment where the plugin is deployed.

CVE advisoryCRITICAL

CVE-2026-86710

Login with QR WordPress Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin has a critical authentication bypass vulnerability where it fails to validate QR code credentials, allowing unauthenticated attackers to log in as any user, including administrators. This could lead to unauthorized access and potential site compromise. The primary concern is determining if this plugi

CVE advisoryCRITICAL

CVE-2026-86709

Pressengine WordPress Plugin Authentication Bypass Leading to Administrator Login

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Pressengine WordPress plugin has a critical authentication bypass vulnerability. Attackers can log in as any user, including administrators, without valid credentials because the login handler issues a session even upon authentication failure. This allows for unauthorized account takeover and site control if the pl

CVE advisoryCRITICAL

CVE-2026-87796

WordPress Multi Uploader Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WordPress plugin allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution. This issue stems from insufficient file type validation during upload handling. Confirmation of the plugin's presence and accessibility within the environment is necessary to a