NVD disclosure day

Published threat advisories for September 26, 2026

CVE advisoryCRITICAL

CVE-2026-82901

Ultra Addons for Contact Form 7 Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Ultra Addons for Contact Form 7 WordPress plugin allows unauthenticated attackers to upload arbitrary files, potentially enabling remote code execution. This vulnerability is only exploitable if the PDF Generator module, which is disabled by default, is enabled. It is important to verify

CVE advisoryCRITICAL

CVE-2026-85984

WordPress miniOrange OTP Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the miniOrange OTP Login plugin for WordPress allows unauthenticated attackers to bypass administrator logins by exploiting specific, conditional plugin settings. If an attacker knows a username and the site has the necessary plugin options enabled, they can gain administrator access without

CVE advisoryCRITICAL

CVE-2026-97163

Joomla UP Plugin Unauthenticated Remote Code Installation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a Joomla UP plugin extension that allows unauthenticated remote code installation. This means an attacker could potentially execute arbitrary code on a website without needing any credentials. This could impact the integrity and availability of the website and its underlying system.

CVE advisoryCRITICAL

CVE-2026-97161

Joomla UP Plugin Path Traversal and File Access Vulnerabilities.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a Joomla plugin that may allow unauthorized access to files and directories. If reachable, an unauthenticated attacker could potentially read arbitrary server files, leading to information disclosure. Confirming the presence and reachability of the affected plugin on your Joomla sites is advis

CVE advisoryCRITICAL

CVE-2026-94132

AcyMailing Enterprise Remote Code Execution Via Unchecked File Uploads

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the AcyMailing Enterprise Joomla extension. Attackers can exploit this by sending crafted emails to a monitored mailbox, leading to the upload and execution of PHP files on the web server. This poses a risk to the integrity of web applications and server security

CVE advisoryCRITICAL

CVE-2026-94130

Joomla YouTube Gallery Extension SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An SQL injection vulnerability exists in the YouTube Gallery Joomla extension, allowing unauthenticated attackers to inject SQL commands through video search and sorting functions. This could potentially lead to unauthorized access or modification of the website's database.

CVE advisoryCRITICAL

CVE-2026-100716

Froxlor Path Traversal Leads to Root Compromise.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Froxlor server administration panel allows authenticated users to gain root access and compromise other tenants. This occurs due to improper handling of path components in the data export function, enabling an attacker to escalate privileges by creating symbolic links. The compromise impacts conf

CVE advisoryCRITICAL

CVE-2026-100714

Froxlor LetsEncrypt Path Traversal Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Froxlor, a server management platform, allows authenticated administrators to execute arbitrary commands as root. This is due to improper handling of the `system.letsencryptchallengepath` setting, enabling command injection during scheduled Let's Encrypt operations. The issue is significant

CVE advisoryCRITICAL

CVE-2026-100606

Flowise Authentication Bypass via SSO Email Match

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical authentication bypass exists in Flowise when using SSO with invited users. An attacker can hijack an invitation by authenticating through a configured SSO provider with an invited user's email, gaining unauthorized access to their account and organization membership. This bypass is possible for as long as th