NVD disclosure day

Published threat advisories for September 28, 2026

CVE advisoryCRITICAL

CVE-2026-101110

Joomla Book Library Unauthenticated SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated SQL injection vulnerability exists in a Joomla extension due to insufficient sanitization of user input used in database queries. Attackers could exploit this to manipulate data or gain unauthorized access to the database. Confirming the extension's use and external exposure is crucial, as th

CVE advisoryCRITICAL

CVE-2026-49994

Bluehood API Unauthenticated Access to Bluetooth Data and State

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Bluehood allowed network attackers to access and modify Bluetooth tracking data and application settings without authentication. This could result in unauthorized reading of sensitive information and alteration of critical configurations.

CVE advisoryCRITICAL

CVE-2026-101891

WatchGuard Access Point Internal API Session Theft Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper access control vulnerability in an internal API service on WatchGuard Access Points may allow an unauthenticated attacker with network access to obtain a valid API session. If the internal API is reachable, this could lead to unauthorized access. The relevance of this internal service to the network's secur

CVE advisoryCRITICAL

CVE-2026-88804

Rancher UI Stored Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical stored cross-site scripting vulnerability exists in the Rancher UI, allowing unauthenticated remote attackers to execute malicious code by updating public settings. This could lead to a compromise of users' sessions and application control, impacting the confidentiality, integrity, and availability of the pl

CVE advisoryCRITICAL

CVE-2026-101075

Netcore NR289-GE Location Time Handler OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Netcore routers allows remote attackers to inject and execute operating system commands via the Location Time Handler. This could lead to a full device compromise. The issue is publicly disclosed, and the vendor has not responded.

CVE advisoryCRITICAL

CVE-2026-73642

Dayforce Payroll Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Dayforce Payroll's file download functionality allows an unauthenticated attacker to access sensitive files by sending a crafted GET request with an absolute local file path. This could lead to unauthorized disclosure of information. The vulnerability has been confirmed in one version

CVE advisoryCRITICAL

CVE-2026-73640

Dayforce Payroll Blind SQL Injection in Password Recovery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Dayforce Payroll has a critical vulnerability in its password recovery function that allows unauthenticated attackers to inject malicious SQL commands. This can potentially lead to unauthorized access or manipulation of sensitive data. Confirmation of affected versions beyond R2026.2.0 is pending.

CVE advisoryCRITICAL

CVE-2026-82384

Apache Roller XML-RPC Deserialization Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A deserialization vulnerability in Apache Roller's XML-RPC endpoint allows unauthenticated remote attackers to execute code by sending specially crafted data. This issue is reachable before authentication and impacts systems where the XML-RPC endpoint is accessible, potentially leading to remote code execution.

CVE advisoryCRITICAL

CVE-2026-101001

Netcore NBR200V2 OS Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the Web Management Interface of a Netcore router allows remote attackers to execute arbitrary commands by manipulating a specific argument. The exploit is publicly available, and the vendor has not responded. This could impact the device's network services and integrity.