NVD disclosure day

Published threat advisories for September 21, 2026

CVE advisoryCRITICAL

CVE-2026-78847

JavaScript Engine in gray-matter Allows Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the JavaScript engine of gray-matter when parsing front matter with a JavaScript language specifier. This could allow for arbitrary code execution if reachable, potentially affecting system data and service behavior. This is a concern for systems that process files using this library.

CVE advisoryCRITICAL

CVE-2026-94572

OpenStack Octavia Amphora Driver Configuration Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenStack Octavia's Amphora provider driver has a flaw allowing authenticated users to inject arbitrary HAProxy commands via TLS cipher settings. This impacts deployments using the Amphora provider and could affect security and operations. Confirming relevance and exposure is key.

CVE advisoryCRITICAL

CVE-2026-94571

OpenStack Octavia HAProxy Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

In OpenStack Octavia, a vulnerability exists in the Amphora provider driver that allows an authenticated user to inject arbitrary HAProxy directives. This occurs when control characters are present in L7 policy redirect fields, as Octavia fails to properly sanitize them before generating HAProxy configurations. Deploym

CVE advisoryCRITICAL

CVE-2026-88404

Univer UniscriptExecutionService Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in a script execution service function within Univer. Attackers could exploit this by sending a crafted payload to execute arbitrary code, potentially impacting system integrity and availability. Further assessment is needed to determine if this specific service is

CVE advisoryCRITICAL

CVE-2026-88402

NocoBase SQL Injection Vulnerability Allows Database Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in nocobase's checkSQL function could allow unauthorized access to sensitive database information by injecting crafted SQL statements. This issue is concerning because such platforms are often internet-exposed, potentially enabling attackers to exfiltrate data. Confirming the use of nocoba

CVE advisoryCRITICAL

CVE-2026-79916

MaxKB AWS Credential Injection via Control Characters Allows Root Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated MaxKB AI assistant user can inject control characters into AWS credential fields, leading to the execution of attacker-controlled commands as root. This vulnerability impacts the confidentiality, integrity, and availability of the system if reachable. Organizations should confirm if affected versions o

CVE advisoryCRITICAL

CVE-2026-77521

MaxKB Command Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MaxKB, an open-source AI assistant, has a vulnerability that allows untrusted input to trigger unauthorized command execution without human approval. This could lead to compromised systems, impacting confidentiality, integrity, and availability. Confirm your use of MaxKB and assess potential exposure.

CVE advisoryCRITICAL

CVE-2026-67827

ZLMediaKit HTTP API Improper Access Control Leading to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in ZLMediaKit's HTTP API module, allowing unauthenticated remote attackers to execute arbitrary commands on affected systems by overwriting configuration settings. This could lead to a complete compromise of the server, impacting confidentiality, integrity, and availability. It is import

CVE advisoryCRITICAL

CVE-2026-46649

Joplin Server Authentication Code Brute Force Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Joplin Server's authentication endpoint can be exploited by an unauthenticated attacker to gain access to user data. The vulnerability allows for unlimited guesses of a short-lived SSO authentication code during an active login attempt, potentially resulting in the issuance of a session token. This token could permit u

CVE advisoryCRITICAL

CVE-2026-58491

Warpgate SSO Open Redirect and Cross-Site Scripting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Warpgate, an open-source bastion host, has a vulnerability where crafted links can execute malicious code within an authenticated session, potentially exposing sensitive data and enabling unauthorized actions. An open redirect is also possible. Confirmation of Warpgate usage and exposure is necessary to assess risk.

CVE advisoryCRITICAL

CVE-2026-93012

Email::Sender::Transport::Sendmail Command Execution on Windows

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in a Perl email library allows attackers to execute commands on Windows by sending specially crafted email. This occurs when email addresses are passed to the system shell, enabling command injection. Applications using this library to send emails on Windows could be affected.

CVE advisoryCRITICAL

CVE-2026-79920

Ajenti Plugin Installation Allows Root Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Ajenti, a server administration panel, has a critical vulnerability allowing authenticated users to achieve root code execution and full host compromise. This occurs when specific plugin management tasks are enqueued without proper authorization, enabling manipulation of package installations.

CVE advisoryCRITICAL

CVE-2026-61674

Fluent Bit Heap-Based Buffer Overflow Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Fluent Bit, a log and data processor, contains a vulnerability where an attacker controlling or impersonating a Secure Forward destination can send oversized data during a handshake. This can overwrite stack data, potentially leading to remote code execution as the Fluent Bit process user, especially in certain configu

CVE advisoryCRITICAL

CVE-2026-85751

Mailu Authentication Bypass via Trusted Header Spoofing

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in Mailu, an email server, allowing unauthenticated remote attackers to spoof trusted proxy identities and gain unauthorized access. This issue affects specific configurations where a client-controlled header is trusted for proxy authentication. Mailu deployments with certa

CVE advisoryCRITICAL

CVE-2026-94301

Apache MINA 2.0 and 2.1 Filter Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A previous fix for a vulnerability in Apache MINA was incomplete, leaving certain versions susceptible to an allow-list bypass. This vulnerability could allow an unauthenticated remote attacker to bypass security checks, potentially leading to unauthorized actions or system compromise. Readers should verify if their or

CVE advisoryCRITICAL

CVE-2026-86473

Apache Airflow API logout flaw allows stolen session tokens to remain valid.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Apache Airflow's API allows session tokens to remain valid after logout if presented in an Authorization header, enabling an attacker with a stolen token to maintain access. This affects API clients using bearer tokens and could lead to continued unauthorized access until the token expires. Uncertain

CVE advisoryCRITICAL

CVE-2025-12999

Open VSX Cache Poisoning Allows Malicious Extension Installation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can poison the Open VSX registry's cache by forging request headers, leading to users downloading and installing malicious extensions. This occurs because the system improperly uses forwarded host information to construct URLs, which are then cached and served to all clients. The expl

CVE advisoryCRITICAL

CVE-2026-82187

WordPress Web to Print Designer Arbitrary File Upload Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in a WordPress design plugin allows unauthenticated attackers to upload arbitrary files, including malicious code, to the server. This could permit attackers to run their own code on the server. This issue is relevant to any organization using the affected plugin for web-based design and file uploads.

CVE advisoryCRITICAL

CVE-2026-94097

Netcore NBR200V2 Command Injection via CGI Diagnostic Endpoint.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in the CGI Diagnostic Endpoint of Netcore NBR200V2 devices. Remote attackers can exploit this by manipulating arguments, potentially executing arbitrary commands on the device. The exploit is publicly disclosed, increasing risk.