CRITICAL
9.3 CVE-2026-67921 Published 18 Aug 2026
Halo CMS CSRF Vulnerability Allows Arbitrary Code Execution
Worried this affects one of your servers?
A Cross-Site Request Forgery (CSRF) vulnerability has been found in Halo CMS versions up to 2.25.4.
The issue is present in the CorsConfigurer.java and CsrfConfigurer.java components, and could allow a remote attacker to execute arbitrary code.
Reference: CVE-2026-67921 on NVD
← Back to Security News