NVD disclosure day

Published threat advisories for September 24, 2026

CVE advisoryCRITICAL

CVE-2026-97230

Perl IO::Socket::SSL::SelfCertificate Executes Obfuscated Python Code

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a Perl module allows arbitrary Python code execution when a specially crafted certificate file is processed. This occurs because the code retrieves and runs obfuscated Python from a URL without saving a file, posing a risk if the function is invoked in affected environments.

CVE advisoryCRITICAL

CVE-2026-13016

ServiceNow AI Platform SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A SQL injection vulnerability in the ServiceNow AI Platform could allow unauthenticated users to run arbitrary SQL commands. This might lead to unauthorized access to or modification of sensitive instance data. ServiceNow has issued security updates. Customers should apply these updates promptly to mitigate potential r

CVE advisoryCRITICAL

CVE-2026-61741

http4s-scala-xml XXE Vulnerability Allows File Disclosure and SSRF.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The http4s-scala-xml library's XML decoders, when parsing untrusted data without security configurations, are vulnerable to XML External Entity (XXE) attacks. This could allow attackers to disclose local files, perform server-side request forgery against internal resources, or cause denial of service. This is a concern

CVE advisoryCRITICAL

CVE-2026-61604

ixo Blockchain x/bonds Module Stolen Funds Vulnerability Exploited on Mainnet

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the ixo Blockchain's x/bonds module allowed attackers to misappropriate funds by linking victim addresses to attacker-controlled bonds. This flaw impacted accounts holding tokens used in bonds and was exploited on the mainnet. The issue is fixed in version 8.0.0, which disables the affected

CVE advisoryCRITICAL

CVE-2026-97413

Linux Kernel RDMA Integer Underflow Leads to Out-of-Bounds Memory Access

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's RDMA transport service allows an unauthenticated network attacker to cause an integer underflow by sending crafted messages, leading to out-of-bounds memory access. This could potentially result in unauthorized memory manipulation or service instability. Its relevance depends on th

CVE advisoryCRITICAL

CVE-2026-90481

PortSwigger Burp Suite DAST Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An authentication bypass vulnerability exists in PortSwigger Burp Suite DAST that could allow unauthorized access. This issue occurs via an alternate path or channel, and its impact depends on the product's deployment and reachability within your environment. Readers should confirm if this technology is in use and asse

CVE advisoryCRITICAL

CVE-2026-91187

Nimble ZTA Improper Signature Verification Allows Cloudflare Token Impersonation.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in the nimble_zta library allows an unauthenticated remote attacker to impersonate any Cloudflare service token by sending a forged JWT. This could lead to unauthorized access to applications using the Cloudflare Zero Trust authentication strategy.

CVE advisoryCRITICAL

CVE-2026-18467

Paytium WordPress Plugin Privilege Escalation Allows Site Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical privilege escalation vulnerability in the Paytium WordPress plugin could allow unauthenticated attackers to gain administrator control of a site by exploiting publicly accessible payment forms. This allows attackers to register a new administrator account and fully take over the site. The issue requires the