NVD disclosure day

Published threat advisories for September 22, 2026

CVE advisoryCRITICAL

CVE-2026-18163

IBM FTM for Red Hat OpenShift Arbitrary Code Execution via Improper Deserialization.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

IBM Financial Transaction Manager for Red Hat OpenShift has a critical vulnerability allowing remote code execution due to improper deserialization of untrusted data. This means an attacker could potentially run their own code on the system if the vulnerability is reachable. Understanding if your deployment is affected

CVE advisoryCRITICAL

CVE-2026-18162

IBM Financial Transaction Manager Arbitrary Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in IBM Financial Transaction Manager for Red Hat OpenShift allows remote attackers to execute arbitrary code by improperly handling user input. This could impact the integrity and availability of financial transaction processing systems. Readers should care because it affects critical financial

CVE advisoryCRITICAL

CVE-2026-89282

Apache Lounge Windows Installer Directory Permissions Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Apache HTTP Server on Windows has an insecure installation directory vulnerability, allowing authenticated users to write to the default installation path. This could enable the modification of server files, potentially leading to further system compromise. The risk hinges on whether this specific configuration is

CVE advisoryCRITICAL

CVE-2026-75745

Adobe Experience Manager Forms JEE Authorization Flaw Allows Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Experience Manager Forms JEE has an authorization vulnerability enabling unauthenticated attackers to execute arbitrary code remotely. This flaw could compromise system integrity and availability if network services are accessible.

CVE advisoryCRITICAL

CVE-2026-75697

Adobe Connect Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Connect has a stored cross-site scripting vulnerability allowing attackers to inject malicious scripts into form fields. If reachable, these scripts could execute in a user's browser, potentially leading to unauthorized access or control of their account or session. Confirming your environment's exposure is key t

CVE advisoryCRITICAL

CVE-2026-75689

Adobe Connect Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Connect has a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into form fields. If exploited, these scripts can execute in a user's browser, potentially leading to unauthorized access or control of their account or session. Confirm if Adobe Connect is in use to assess p

CVE advisoryCRITICAL

CVE-2026-75684

Adobe Connect Stored XSS Vulnerability Allows Script Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Connect has a stored Cross-Site Scripting vulnerability that allows attackers to inject malicious scripts into form fields. When a user accesses a page with a vulnerable field, these scripts can execute in their browser, potentially leading to elevated access or control over their account or session.

CVE advisoryCRITICAL

CVE-2026-75723

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is affected by an incorrect authorization vulnerability that could allow an unauthenticated attacker to execute arbitrary code remotely without user interaction. This critical flaw could impact system data and service behavior.

CVE advisoryCRITICAL

CVE-2026-75721

Adobe Campaign Classic Code Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe Campaign Classic is susceptible to code injection, potentially allowing an attacker to execute arbitrary code without user interaction. This vulnerability impacts a core marketing automation platform, raising concerns about system integrity and confidentiality if network-accessible instances are reachable.

CVE advisoryCRITICAL

CVE-2026-80156

Lantronix Path Traversal Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Lantronix web management portals allows authenticated attackers to write arbitrary files to any filesystem location, leading to remote code execution. This could result in a complete loss of device confidentiality, integrity, and availability, potentially affecting downstream connected

CVE advisoryCRITICAL

CVE-2026-80155

Lantronix Authentication Bypass Allows Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Lantronix web management portals, allowing unauthenticated attackers to bypass security and execute remote code. This could lead to a complete loss of confidentiality, integrity, and availability for affected devices and potentially impact downstream systems.

CVE advisoryCRITICAL

CVE-2026-80147

Lantronix Unauthenticated Code Execution via Stack Buffer Overflow.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A stack-based buffer overflow vulnerability exists in Lantronix management devices, allowing authenticated attackers to execute arbitrary code. This could lead to a complete loss of confidentiality, integrity, and availability for the affected device and any downstream serial-attached equipment.

CVE advisoryKnown Exploit

CVE-2026-94127

F5 BIG-IP APM Remote Code Execution via OAuth Profile

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in BIG-IP APM when configured as an OAuth Authorization Server, allowing unauthenticated attackers to execute remote code via specific malicious traffic. This data plane issue impacts systems performing authorization functions and requires assessment of external exposure and business cri

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-65118

NVIDIA Infrastructure Controller Improper Certificate Validation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper certificate validation vulnerability exists in NVIDIA Infrastructure Controller for Linux. This could allow an attacker to disclose sensitive information, tamper with data, or disrupt service if the controller is reachable.

CVE advisoryCRITICAL

CVE-2026-65113

NVIDIA Infrastructure Controller Hard-Coded Credentials Vulnerability Leads to Privilege Escalation and Data Tampering

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in NVIDIA's Infrastructure Controller for Linux concerning hard-coded credentials. If reachable, an attacker could exploit this to escalate privileges, tamper with data, cause denial of service, or disclose information. This could impact the integrity and availability of systems managed by the co

CVE advisoryCRITICAL

CVE-2026-95675

D-Link DAP-1360 Unauthenticated Root Command Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote code execution vulnerability exists in the web management interface of certain D-Link devices. This flaw allows attackers to execute commands with the highest privileges, potentially leading to full device compromise and use as a pivot point into the local network. The main concern at this tim

CVE advisoryKnown Exploit

CVE-2026-93616

Check Point Management Server Directory Traversal and Script Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in Check Point management software allows unauthenticated attackers to upload and execute arbitrary scripts. This could impact server integrity and availability, necessitating confirmation of product deployment and network exposure.A directory traversal vulnerability in Check Point m

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-93556

Password Recovery Endpoint JWT Validation Flaw Allows Account Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in a password recovery endpoint allows unauthenticated attackers to reset any user's password, including administrative accounts, by manipulating a user identifier. This could lead to unauthorized account control. The affected technology is a password recovery function, and the issue stems from a JWT to

CVE advisoryCRITICAL

CVE-2026-87080

Perl Net::IDN::Punycode Decoding Flaw Allows Divergent Name Resolution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in a Perl library for internationalized domain names that may cause it to misinterpret encoded labels, potentially leading to divergent name resolution. This could allow a sender to craft a label that one system resolves and another rejects, impacting name resolution or service behavior. Assess t

CVE advisoryCRITICAL

CVE-2026-94493

Gigatech PDV5701 Missing Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Gigatech PDV5701 devices, allowing remote attackers to bypass authentication via manipulation of the WebSocket Service's `/index.html` file. The exploit is publicly available, and the vendor has not responded to disclosures. This could lead to unauthorized access or control of affecte