CVE-2026-67921
the affected product
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.
- CVSS
- 9.3
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19