NVD disclosure day

Published threat advisories for September 20, 2026

CVE advisoryCRITICAL

CVE-2026-94089

D-Link DIR-868L Authentication Handler Stack Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in a D-Link router's authentication handler, allowing remote attackers to cause a stack-based buffer overflow by manipulating login credentials. This issue is publicly disclosed and exploitable, potentially impacting device functionality. It is important to identify if this specific rout

CVE advisoryCRITICAL

CVE-2026-88857

Joomla OrdaSoft Gallery RCE via File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a Joomla extension allows authenticated, privileged users to upload and execute code. If reachable, an attacker could upload a malicious PHP file disguised as an image, leading to remote code execution. This is a concern for environments using this specific Joomla extension, requiring confirmation of

CVE advisoryCRITICAL

CVE-2026-88856

Joomla OrdaSoft Gallery Remote Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in an OrdaSoft Joomla extension that allows privileged users to execute arbitrary code on the server. This occurs when the extension processes a JSON request by calling a PHP function directly, without validation. While this requires administrative access, it could lead to a compromise of system

CVE advisoryCRITICAL

CVE-2026-90817

RECAP Unauthenticated Remote Code Execution via Survey Routing and Data Import.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in REDCap's survey and data import logic allows unauthenticated attackers to execute arbitrary code on the server by manipulating HTTP requests. This could lead to server compromise if a public survey hash is known.

CVE advisoryCRITICAL

CVE-2026-94107

NivoCart Predictable Password Reset Token Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A predictable password reset token vulnerability exists in NivoCart's forgotten password endpoint. Attackers aware of an administrator's email could potentially predict the recovery code to gain unauthorized administrative access to the system. This affects the security of administrative accounts within the NivoCart e-

CVE advisoryCRITICAL

CVE-2026-94003

Comfast CF-N1-S Stack Buffer Overflow in Web Management Interface

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stack-based buffer overflow vulnerability exists in the web management interface of the Comfast CF-N1-S. Remote, unauthenticated attackers can exploit this by sending malicious input to the `get_css_path_from_uri` function, potentially leading to system compromise. The public disclosure of an exploit increases the ri

CVE advisoryCRITICAL

CVE-2026-94084

Suricata Http2ThreadMultiBuf Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Suricata, a network security monitoring tool, has a critical use-after-free vulnerability in its HTTP/2 traffic inspection. This flaw could allow an attacker to impact data integrity and availability if reachable, necessitating a review of its relevance and exposure within the environment.