NVD disclosure day

Published threat advisories for October 4, 2026

CVE advisoryCRITICAL

CVE-2026-105089

WWBN AVideo Stored Cross-Site Scripting Via Trailer URL

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

WWBN AVideo has a stored cross-site scripting flaw allowing script injection via video trailer URLs. Attackers with upload permissions can embed malicious scripts that execute JavaScript in users' browsers when viewed in templates or playlists. This issue is relevant if your AVideo instances are accessible and users wi

CVE advisoryCRITICAL

CVE-2026-105211

ZITADEL Login V2 Authentication Bypass Allows Account Takeover

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in ZITADEL's Login V2 allows unauthenticated attackers to bypass multi-factor authentication and take over accounts, including administrative ones, by intercepting one-time passcodes. This issue is relevant if your organization uses ZITADEL for identity and access management and you need to assess poten

CVE advisoryCRITICAL

CVE-2026-105209

ZITADEL Cross-Organization Account Takeover via Passkey Enrollment

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

ZITADEL has an improper authorization vulnerability where attackers with user-write permissions in one organization can obtain enrollment codes for users in another organization, leading to account takeover. This allows an attacker to register their authenticator and gain control of another user's account. This is rele

CVE advisoryCRITICAL

CVE-2026-105134

Ahsay Replication Receiver OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection flaw exists in Ahsay's Replication Receiver, allowing remote attackers to execute OS commands via a manipulated API argument. This vulnerability could impact system integrity and availability, posing a significant risk given the published exploit.