NVD disclosure day

Published threat advisories for September 27, 2026

CVE advisoryKnown Exploit

CVE-2026-88772

Citrix NetScaler Remote Code Execution and Denial of Service Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability in Citrix NetScaler ADC and Gateway may permit unauthenticated remote code execution or denial of service. This flaw could impact critical network access and services if affected systems are internet-facing and unpatched, potentially disrupting operations.

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-100741

hMailServer JScript Event Injection Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in hMailServer allows unauthenticated attackers to run arbitrary JScript with service account privileges. This requires specific, non-default event scripting configurations to be enabled, but exploitation can occur through specially crafted passwords or server responses. The main concern is con

CVE advisoryCRITICAL

CVE-2026-100835

Contrast Remote Attestation Relay Attack Defeats Identity Verification

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Contrast's remote attestation process is vulnerable to relay attacks, potentially allowing an attacker to impersonate trusted components and bypass identity verification. This occurs because the system may accept attestation reports without verifying the originating hardware. The vulnerability impacts Contrast's attest