NVD disclosure day

Published threat advisories for October 1, 2026

CVE advisoryCRITICAL

CVE-2026-51886

Langflow Code Injection Vulnerability Allows Arbitrary Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A code injection vulnerability in langflow allows an authenticated attacker to execute arbitrary Python code on the server via an API endpoint. This could compromise service integrity and availability. The affected technology is a web-based application designed for workflows and APIs.

CVE advisoryCRITICAL

CVE-2026-56662

GetSimple CMS Update Form CSRF Leads to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

GetSimple CMS is vulnerable to remote code execution due to a flaw in its update form that lacks anti-CSRF protection. An attacker can exploit this by tricking an administrator into visiting a malicious page, leading to an attacker-directed download and execution of code. This vulnerability also allows for HTML injecti

CVE advisoryCRITICAL

CVE-2026-102628

Cadmos LTI Information Exposure via Debug Mode

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Cadmos LTI application had Laravel debug mode enabled publicly, allowing unauthenticated attackers to trigger an exception and expose server environment details, including configuration variables. This issue was fixed before September 2, 2026, but confirming if your organization uses this application is important t

CVE advisoryCRITICAL

CVE-2026-79901

BoKS Keytab Predictable Password Generation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in BoKS keytab management allows attackers to predict Active Directory service-account passwords if they know the service principal and can estimate the password change time. This predictability could lead to unauthorized access and compromise of services relying on these credentials.

CVE advisoryCRITICAL

CVE-2026-103264

Fleet Authentication Bypass via Device Identifiers.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in a device management API allows unauthenticated attackers to impersonate devices using known identifiers, potentially leading to unauthorized access to device data and control over actions like software installation or MDM migration. Readers should care because this could compro

CVE advisoryCRITICAL

CVE-2026-103655

MISP Two-Factor Authentication Code Reuse Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MISP has a vulnerability in its two-factor authentication where a valid one-time code can be reused within its time window. This could allow an attacker who intercepts a legitimate code to gain unauthorized access to a user's account and potentially sensitive threat intelligence data. It is important to confirm if MISP

CVE advisoryCRITICAL

CVE-2026-14157

ASUS Router Format String Vulnerability Allows Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A format string vulnerability in ASUS router modules allows a remote authenticated user to execute arbitrary commands by uploading a crafted file via the web management interface. This could impact system data and services, making it important to identify if this technology is in use and assess its exposure.