NVD disclosure day

Published threat advisories for October 6, 2026

CVE advisoryCRITICAL

CVE-2026-106372

Chrome UI Vulnerability Allows Potential Arbitrary Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's user interface could allow remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This requires user interaction with a malicious page, potentially affecting user systems and data if exploited.

CVE advisoryCRITICAL

CVE-2026-104070

SPIP Crayons Plugin Authorization Bypass Leading to Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A missing authorization vulnerability in the SPIP Crayons plugin allows unauthenticated attackers to execute arbitrary PHP code. By bypassing security checks, attackers can modify fields, upload malicious files, disclose sensitive information, and gain control of the web server. This poses a significant risk to the int

CVE advisoryCRITICAL

CVE-2026-105794

MsQuic Certificate Validation Bypass Allows Man-in-the-Middle Attacks

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

MsQuic, a QUIC protocol implementation, has a vulnerability where clients using OpenSSL or QuicTLS may not properly verify server certificates. This could allow an attacker to present a mismatched certificate, enabling man-in-the-middle attacks and potential data interception or modification. The Schannel backend is un

CVE advisoryCRITICAL

CVE-2026-42415

Porto Theme Functionality SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Porto theme's functionality, potentially allowing network-accessible attackers to execute malicious SQL code. This could lead to unauthorized access to sensitive data or disruption of the affected web application. The reader should care because this type of v