NVD disclosure day

Published threat advisories for September 19, 2026

CVE advisoryCRITICAL

CVE-2026-93985

OpenPanel js-runtime Sandbox Escape Allows Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A sandbox escape vulnerability in OpenPanel's JavaScript webhook template validator allows attackers with project write access to execute arbitrary code within the worker process. This could impact service behavior when specific webhook templates are processed.

CVE advisoryCRITICAL

CVE-2026-78030

DBI DBD::DBM Arbitrary Module Load Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in a Perl library allows arbitrary module loading via unvalidated connection attributes, potentially leading to arbitrary code execution if an application uses untrusted input in attributes like `dbm_type`. This requires an attacker to influence these attributes, for example, through a DSN fragment. The

CVE advisoryCRITICAL

CVE-2026-93741

Totolink A3002MU Buffer Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability exists in Totolink wireless routers within a network-accessible web management function. Successful remote exploitation of this flaw could allow an attacker to compromise the device, posing a risk to system integrity and potentially enabling unauthorized code execution or denial-of-servi

CVE advisoryCRITICAL

CVE-2026-92229

Forminator WordPress Plugin Arbitrary Shortcode Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability exists in the Forminator WordPress plugin that allows unauthenticated attackers to execute arbitrary shortcodes by submitting specially crafted input. This occurs because the plugin does not properly validate user-provided data before processing it. This could potentially impact site content and behavio

CVE advisoryCRITICAL

CVE-2026-89274

WP Recipe Maker Arbitrary Shortcode Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the WP Recipe Maker WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes on recipe pages. This can lead to the disclosure of sensitive information embedded within the recipe's metadata, accessible to anyone viewing the page, provided an attacker's comment containing the m

CVE advisoryCRITICAL

CVE-2026-84434

Gravity Forms WordPress Plugin Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Gravity Forms plugin for WordPress has a vulnerability that allows unauthenticated attackers to upload executable files, potentially leading to remote code execution. This issue arises from a flaw in how file uploads are validated and persisted. The vulnerability is reachable on any publicly accessible form with a