CRITICAL 9.3 CVE-2026-67921 Published 18 Aug 2026

Halo CMS CSRF Vulnerability Allows Arbitrary Code Execution

Worried this affects one of your servers?

A Cross-Site Request Forgery (CSRF) vulnerability has been found in Halo CMS versions up to 2.25.4.

The issue is present in the CorsConfigurer.java and CsrfConfigurer.java components, and could allow a remote attacker to execute arbitrary code.

Reference: CVE-2026-67921 on NVD

← Back to Security News