NVD disclosure day

Published threat advisories for September 18, 2026

CVE advisoryCRITICAL

CVE-2026-93740

Totolink A3002MU Buffer Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical buffer overflow vulnerability exists in Totolink wireless routers within the formWlEncrypt function. This flaw allows unauthenticated, remote attackers to potentially execute arbitrary code or cause denial-of-service conditions, with publicly available exploit code increasing the likelihood of its misuse.

CVE advisoryCRITICAL

CVE-2026-75885

OpenShift Console SSRF and DoS Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the OpenShift console allows unauthenticated remote attackers to exploit specific endpoints, potentially leading to server-side request forgery and denial of service. This could expose internal services or disrupt operations. Confirmation of relevance and exposure to specific OpenShift deployments is

CVE advisoryCRITICAL

CVE-2026-93868

Cotonti Predictable Password Recovery Token Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can reset any account's password in Cotonti by predicting password recovery tokens. This allows unauthorized access to sensitive information and system control. Confirm if Cotonti is in use and assess its exposure to understand the risk.

CVE advisoryCRITICAL

CVE-2026-93839

LightLLM Authentication Bypass in WebSocket Registration Endpoint

Halo Surface Signal: 3 out of 5 — possibly public-facing.

LightLLM software has an authentication bypass vulnerability in a WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes. This could lead to the disclosure of user prompts, denial of service, or the system making requests to internal network addresses. The relevance and potential exposure

CVE advisoryCRITICAL

CVE-2026-84075

IBM Guardium Data Protection Missing Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a vulnerability where a remote attacker can bypass security restrictions due to missing authentication. This could impact the integrity and availability of protected data and potentially lead to unauthorized access to sensitive information.

CVE advisoryCRITICAL

CVE-2026-84073

IBM Guardium Data Protection SQL Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a critical vulnerability allowing authenticated users to execute arbitrary SQL commands due to improper input handling. This could compromise the integrity and confidentiality of protected data and the Guardium system itself. The relevance depends on network accessibility and the specif

CVE advisoryCRITICAL

CVE-2026-84064

IBM Guardium Data Protection SQL Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a vulnerability allowing authenticated users to execute arbitrary SQL commands due to improper SQL command neutralization. This could impact the confidentiality and integrity of managed data. Organizations should confirm if this product is in use and assess its network exposure.

CVE advisoryCRITICAL

CVE-2026-84031

IBM Guardium Data Protection Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a vulnerability allowing an authenticated user to potentially execute arbitrary code through improper web page input handling. This could impact system integrity and availability if the web interface is reachable. It's important to determine if this technology is deployed and exposed in

CVE advisoryCRITICAL

CVE-2026-82967

IBM Guardium Data Protection Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can bypass IP access controls to access the IBM Guardium Data Protection management interface. This could lead to unauthorized access to sensitive data if the system is reachable. The relevance and exposure of Guardium instances should be confirmed.

CVE advisoryCRITICAL

CVE-2026-82832

IBM Guardium Data Protection Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a vulnerability allowing authenticated attackers to execute arbitrary code due to improper input handling in its web page generation. This could impact system data and behavior if the web interface is reachable and exploited. Reviewing its exposure is important.

CVE advisoryCRITICAL

CVE-2026-81657

IBM Guardium Data Protection Code Execution via Untrusted Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in IBM Guardium Data Protection due to untrusted data deserialization, potentially allowing unauthenticated remote attackers to execute arbitrary code. This could compromise system integrity and confidentiality if the affected system is reachable over the network.

CVE advisoryHIGH

CVE-2026-80442

IBM Guardium Data Protection 12.2 OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated OS command injection vulnerability exists in IBM Guardium Data Protection's `exportCertificate` functionality, potentially allowing an attacker to execute unauthorized commands and impact system confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2026-80441

IBM Guardium Data Protection 12.2 SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Guardium Data Protection has a critical SQL injection vulnerability in its generateInsertQuery functionality. A remote attacker could inject malicious SQL, potentially compromising system confidentiality, integrity, and availability. This issue warrants attention to ensure the security of protected data and system

CVE advisoryCRITICAL

CVE-2026-75878

IBM Sterling File Gateway Improper Authentication Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

IBM Sterling File Gateway has a vulnerability where an unvalidated SSO header could allow a remote attacker to bypass authentication and gain a fully authenticated session. This could expose sensitive data or operations within systems that manage file transfers.

CVE advisoryCRITICAL

CVE-2026-63647

CordysCRM Unauthenticated Access to User Data and Channel Control.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

CordysCRM, an open-source customer relationship management system, has a vulnerability allowing unauthenticated access to user data. Attackers can exploit this to view workflow events, approval requests, mentions, and alerts, or to inject messages and terminate user channels. This could lead to unauthorized access and

CVE advisoryCRITICAL

CVE-2026-61781

pg_partman SQL Injection to PostgreSQL Superuser Compromise.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The pg_partman PostgreSQL extension is vulnerable to SQL injection, allowing a user with specific database privileges to execute arbitrary SQL. This could lead to full database compromise and operating system command execution as the PostgreSQL superuser. The reachability of this vulnerability is considered very unlike

CVE advisoryCRITICAL

CVE-2026-58264

FluidSynth Heap Write Vulnerability Leading to Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in FluidSynth's command handler that can lead to an out-of-bounds heap write, potentially causing denial of service or code execution. This issue is remotely reachable if the TCP server is enabled, or locally via the FluidSynth shell. Applications not using these features are unaffected.

CVE advisoryCRITICAL

CVE-2023-54399

Hongjing e-HR SQL Injection Allows Database Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in Hongjing e-HR allows unauthenticated attackers to read arbitrary database content, including credentials. This issue arises from an unsanitized query parameter in a web endpoint that may be externally reachable. Readers should care because unauthorized access to sensitive employee data

CVE advisoryCRITICAL

CVE-2026-93762

Mongoid Unsafe Reflection Vulnerability Allows Data Disclosure and Deletion.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A weakness in the Mongoid query path may allow an unauthenticated party to disclose or delete stored document data when an application passes external field names to certain query methods. This issue affects applications using the Mongoid library, and its impact depends on how those applications handle user-provided qu

CVE advisoryCRITICAL

CVE-2026-92701

Cocos AI Session Misbinding Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Cocos AI's confidential computing system could permit session misbinding, potentially leading to the release of application data into unintended attestation contexts. This issue stems from an incorrect validation of security attestations during communication.

CVE advisoryCRITICAL

CVE-2026-61550

Icinga 2 Certificate Handling Vulnerability Allows Node Impersonation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated network attacker could exploit a vulnerability in Icinga 2 by impersonating trusted nodes through certificate manipulation on TCP port 5665, potentially leading to node control. This is relevant for organizations using Icinga 2 for system monitoring.An unauthenticated network attacker can exploit Ici

CVE advisoryCRITICAL

CVE-2026-59163

Mnemosyne Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Mnemosyne memory layer for AI agents has a vulnerability where its sync server could incorrectly accept forged authentication tokens, potentially allowing unauthorized access to AI agent data. This issue could affect data integrity and confidentiality if the sync server endpoint is network-reachable and not secured

CVE advisoryCRITICAL

CVE-2025-66455

LMDeploy PyTorch DistServe Unsafe Deserialization Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

LMDeploy's PyTorch DistServe component has a vulnerability that allows unauthenticated remote code execution when a specific disaggregated serving path is enabled. An attacker could exploit this by sending a crafted message to trigger unsafe deserialization, potentially compromising the LMDeploy serving process. This i

CVE advisoryCRITICAL

CVE-2026-85497

CareCam CM2507 Fixed Password Hash Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

This critical vulnerability affects IP cameras, where a weak password storage method allows offline cracking of the root account password. An attacker could recover credentials, potentially reusing them across devices with the same firmware. It is important to confirm if affected devices are in use and assess any poten

CVE advisoryCRITICAL

CVE-2026-81321

CM2507 IP Camera Cleartext Credential Storage Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

CM2507 IP cameras store wireless network credentials in cleartext. An attacker with filesystem access could recover these credentials, potentially compromising network security. This vulnerability requires further access beyond standard network exposure, and its relevance depends on device deployment and access control

CVE advisoryCRITICAL

CVE-2026-77240

WACRM privilege escalation and unauthorized knowledge access vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in WACRM, a self-hostable CRM template, allows authenticated users to escalate privileges or access another tenant's data. This occurs due to flawed database security policies. If reachable, this could lead to unauthorized modification or exposure of sensitive tenant resources and knowledge.

CVE advisoryCRITICAL

CVE-2026-84383

libheif Heap Out-of-Bounds Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap out-of-bounds write vulnerability exists in the libheif library when processing specially crafted HEIF, HEIC, or AVIF files. This could allow remote attackers to cause memory corruption, potentially impacting system integrity and availability. The relevance and exposure of this issue depend on how applications i

CVE advisoryCRITICAL

CVE-2026-75031

Interchange Quick Question Admin RCE Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in an administrative feature of the interchange project, allowing unauthenticated users to execute arbitrary Perl code server-side if a non-default configuration is enabled. This could lead to server compromise, and its relevance depends on whether this feature is e

CVE advisoryCRITICAL

CVE-2026-61682

kcp Front-Proxy Impersonation and Authorization Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The kcp front-proxy has a vulnerability where it does not properly validate and remove inbound identity headers. This allows an authenticated user to inject forged headers, impersonating other users or gaining elevated privileges. This could lead to unauthorized access, modification, or deletion of resources, secrets,

CVE advisoryCRITICAL

CVE-2026-10858

IBM MQ Heap Buffer Underflow Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap buffer underflow vulnerability in IBM MQ for HPE NonStop, triggered by specially crafted multi-segment messages, could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code. This impacts the integrity and availability of the messaging service. It is uncertain if this

CVE advisoryCRITICAL

CVE-2026-10747

IBM MQ Appliance Heap Buffer Overflow Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in IBM MQ Appliance due to a heap buffer overflow in protocol message processing before authentication, which could allow a remote attacker to cause a denial of service or potentially execute arbitrary code. This could impact the availability and integrity of messaging services.

CVE advisoryCRITICAL

CVE-2025-53837

XWiki Rendering Script Macro Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in XWiki Rendering allows authenticated users to execute arbitrary scripts, including remote code execution with unrestricted access to wiki content. This occurs because rendered output within HTML macros is not properly escaped, enabling attackers to inject malicious script macros. This issue impacts s

CVE advisoryCRITICAL

CVE-2025-15399

IBM Common Licensing Agent Cross-Site Request Forgery Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Common Licensing Agent is vulnerable to cross-site request forgery, potentially allowing attackers to execute unauthorized actions by tricking trusted users. The relevance and exposure of this licensing technology require confirmation to understand potential business impact.

CVE advisoryHIGH

CVE-2026-93659

Concrete CMS Community Store Stored Cross-Site Scripting Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Concrete CMS Community Store allows unauthenticated attackers to inject script payloads into customer order fields, which can execute in authenticated manager sessions. This could lead to the creation of rogue accounts or the exfiltration of data. Confirmation is needed regarding the use and internet

CVE advisoryCRITICAL

CVE-2026-93606

vm2 Sandbox Escape via Host Promise `Symbol.species` Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A sandbox escape vulnerability exists in the vm2 JavaScript library, allowing code within the sandbox to execute arbitrary code on the host system. This occurs when a host API exposes a promise, and the library's handling of these promises doesn't fully sanitize rejections, potentially allowing an attacker to bypass se

CVE advisoryCRITICAL

CVE-2026-93605

vm2 NodeVM Sandbox Escape via Child Process Remote Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A sandbox escape vulnerability in the vm2 NodeVM library allows attackers to execute arbitrary commands on the host system if certain configurations are met. This could lead to unauthorized operations and affect system integrity when untrusted code is processed. Identifying where this technology is implemented and how

CVE advisoryCRITICAL

CVE-2026-93603

vm2 Sandbox Escape Allows Host Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vm2 library has a critical vulnerability that allows sandboxed code to escape its environment and execute arbitrary commands on the host system. This occurs when the application exposes non-strict host functions, and the sandboxed code calls them without a receiver, granting the script access to host global objects

CVE advisoryCRITICAL

CVE-2026-93019

Imager TGA Parsing Out-of-Bounds Read Leads to Process Exit.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in an image processing library where processing a malformed TGA image file can cause an application to unexpectedly exit. This could happen if the library handles user-supplied image data, potentially disrupting service availability.

CVE advisoryCRITICAL

CVE-2023-5778

ABB Freelance Controller Length Parameter Inconsistency Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A length parameter inconsistency vulnerability exists in ABB Freelance Controllers, which are industrial control systems. This flaw could potentially disrupt operations if an attacker sends specially crafted network traffic to a vulnerable controller, leading to a denial-of-service condition. Organizations using these

CVE advisoryCRITICAL

CVE-2026-28198

NetBackup Flex OS Management Shell Signature Bypass Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated user with low privileges in the NetBackup Flex OS management shell can bypass cryptographic signature verification. This grants unrestricted root access, compromising the appliance's confidentiality, integrity, and availability. The vulnerability is externally exposed via the network, but typically suc

CVE advisoryCRITICAL

CVE-2026-28197

NetBackup Flex OS Arbitrary Code Execution via Privileged Command Input

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated, low-privileged user can execute arbitrary code with root privileges on the NetBackup Flex OS management shell by supplying specially crafted input to a privileged administrative command. This grants unrestricted control over the appliance host and hosted containers, potentially compromising confidenti

CVE advisoryCRITICAL

CVE-2026-13639

Synology DSM Insufficient Entropy Login Vulnerability Allows Arbitrary File Access

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An insufficient entropy vulnerability in Synology DiskStation Manager's login logic allows remote attackers to read or write arbitrary files and perform denial-of-service attacks. This critical issue could lead to data compromise or system unavailability, making it important to confirm if affected Synology software is

CVE advisoryCRITICAL

CVE-2026-67101

HCL BigFix SSRF Vulnerability Allows Internal Network Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

HCL BigFix Service Management has a critical Server-Side Request Forgery vulnerability in its search function that could permit an attacker to compel the application server to issue requests to internal systems not typically exposed online. This could potentially lead to unauthorized access to sensitive internal networ

CVE advisoryCRITICAL

CVE-2026-67100

SQL Injection and Cross-Tenant Data Exposure in HCL BigFix Service Management

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

HCL BigFix Service Management has critical vulnerabilities allowing authenticated attackers to inject database commands for system details and manipulate requests for cross-tenant data access, potentially exposing PII. The threat is external and network-exploitable, impacting the confidentiality and integrity of sensit

CVE advisoryCRITICAL

CVE-2026-84738

AF Companion WordPress Plugin Arbitrary File Upload Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the AF Companion WordPress plugin allows users with low-privileged roles to upload arbitrary files, including PHP scripts, through an import feature. This could lead to the execution of malicious code on the affected WordPress site. The issue is relevant if the plugin is in use and its import feature

CVE advisoryCRITICAL

CVE-2026-93467

HGiga OAKlouds Insecure Deserialization Arbitrary Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

HGiga OAKlouds contains an insecure deserialization flaw, enabling unauthenticated remote attackers to execute arbitrary code by sending malicious serialized data. This could lead to server compromise. Confirmation of OAKlouds usage is needed to assess exposure.

CVE advisoryCRITICAL

CVE-2026-69843

Microsoft Fabric Authentication Bypass Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. This could enable an attacker to impersonate legitimate users, potentially leading to unauthorized access to sensitive resources or functionalities. The relevance and exposure of this technol

CVE advisoryCRITICAL

CVE-2026-62874

Azure Billing Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthorized attacker can elevate privileges over a network in Azure Billing due to insufficient data authenticity verification. This critical vulnerability may allow attackers to gain unauthorized access and control. The primary concern is confirming its relevance and exposure within our environment.