NVD disclosure day

Published threat advisories for September 25, 2026

CVE advisoryCRITICAL

CVE-2026-100390

Zoraxy IPv6 Address Parsing Vulnerability Allows Source IP Spoofing

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Zoraxy allows unauthenticated attackers over IPv6 to spoof their source IP address by manipulating forwarded headers. This could bypass IP-based access controls. Readers should confirm if this technology is in use and exposed to such threats.

CVE advisoryCRITICAL

CVE-2026-97063

X-SpringBoot Authentication Bypass Via Exposed Login Codes

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

X-SpringBoot applications may expose login verification codes via unauthenticated HTTP responses, allowing attackers to hijack accounts by intercepting these codes. This vulnerability affects authentication processes and requires confirmation of system relevance and exposure.

CVE advisoryCRITICAL

CVE-2026-84458

Zammad Account Linking Vulnerability Allows Email Spoofing

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Zammad, a web-based customer support system, allows an attacker to gain unauthorized account access by linking a controlled identity from a third-party provider to a victim's email address. This bypasses password requirements and can lead to access to sensitive data.

CVE advisoryCRITICAL

CVE-2026-48482

GLPI Form Import Directory Traversal Leading to Remote Script Invocation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in GLPI software allows an administrator to upload a crafted file that can be written to an executable server location, enabling remote script invocation. This means a malicious script could be executed on the server.

CVE advisoryCRITICAL

CVE-2026-93647

Zimbra Classic Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can exploit a stored cross-site scripting vulnerability in Zimbra Classic. This allows malicious code to be injected into calendar messages, which, when selected by a user, could lead to unauthorized access to mailbox data and actions performed as the victim. Confirmation of the use and expo

CVE advisoryCRITICAL

CVE-2026-93643

OnlyOffice Path Traversal Allows Remote Command Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated remote attacker can execute commands as the `zimbra` user by exploiting unsigned save fields in OnlyOffice/Document Editing to perform path-traversal writes. This vulnerability could lead to unauthorized command execution on the affected system.

CVE advisoryCRITICAL

CVE-2026-100075

Linux Kernel RDMA/srpt Incorrect Counter Update Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The Linux kernel has a vulnerability in its RDMA/srpt component where error handling during context allocation can lead to incorrect accounting of network credits. This could potentially affect system stability and reliability in environments using RDMA-enabled services.

CVE advisoryCRITICAL

CVE-2026-92288

LemonLDAP::NG OAuth2 Token Introspection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in LemonLDAP::NG allows unauthenticated attackers to inspect OAuth2 tokens and their metadata. This bypasses client secret verification for public Relying Parties, enabling attackers to correlate user identifiers across different services and compromise pseudonymous identifiers. This is relevant as it w