NVD disclosure day

Published threat advisories for September 23, 2026

CVE advisoryCRITICAL

CVE-2026-84502

Red Hat Ansible Project URL Injection Command Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Red Hat Ansible Automation Platform's automation controller allows an authenticated user to execute arbitrary commands on the control-plane task pod. This occurs due to improper validation of project URLs, which can be crafted to exploit the git SCM module. Exploitation could lead to cross-tenant com

CVE advisoryCRITICAL

CVE-2026-63132

OpenBao Recovery Token Inference Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenBao, an open-source secrets management system, has a vulnerability where an unauthenticated attacker could infer a recovery token through timing analysis of repeated recovery requests, potentially leading to unauthorized access and modification of sensitive data. The issue is fixed in version 2.6.0.

CVE advisoryCRITICAL

CVE-2026-75799

YAHMAN Add-ons WordPress Plugin Arbitrary File Write Leading to RCE.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the YAHMAN Add-ons WordPress plugin could permit unauthenticated attackers to write arbitrary PHP files to a publicly accessible directory. If the plugin's file caching feature is enabled, this could lead to the execution of malicious code on the server. The relevance depends on the plugin's configur