CRITICAL 9.8 CVE-2026-67919 Published 17 Aug 2026

Halo Plugin Installation Remote Code Execution Vulnerability

Worried this affects one of your servers?

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code. This is a remote code execution vulnerability.

The flaw is reachable through the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components.

Reference: CVE-2026-67919 on NVD

← Back to Security News