CRITICAL
9.8 CVE-2026-67919 Published 17 Aug 2026
Halo Plugin Installation Remote Code Execution Vulnerability
Worried this affects one of your servers?
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code. This is a remote code execution vulnerability.
The flaw is reachable through the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components.
Reference: CVE-2026-67919 on NVD
← Back to Security News