NVD disclosure day

Published threat advisories for October 7, 2026

CVE advisoryCRITICAL

CVE-2026-105324

ADM HTTP Header Injection Vulnerability Allows Arbitrary File Read

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An HTTP header injection vulnerability in ADM allows unauthenticated remote attackers to read arbitrary system files by sending crafted HTTP requests. This impacts ADM systems, potentially those facing the internet, and requires confirmation of system exposure and business criticality for remediation planning.

CVE advisoryCRITICAL

CVE-2026-93674

IBM Langflow OSS OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in IBM Langflow OSS, potentially allowing remote attackers to execute arbitrary code. This issue affects AI/ML workflow tools, raising concerns about system integrity and availability. Confirming usage and exposure is crucial to understanding the potential business i

CVE advisoryCRITICAL

CVE-2026-104334

IBM Langflow Arbitrary Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

IBM Langflow OSS contains a critical vulnerability allowing remote attackers to execute arbitrary code due to improper control of code generation. If reachable, this could impact system integrity and availability. It is important to identify if this software is used and assess its exposure.