Two Next.js Flaws Expose Self-Hosted Servers to Remote Code Execution
Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Read article →The browser extension exposed vault tokens to untrusted page messages. Version 3.49.6 adds origin, frame, and nonce checks; later builds supersede it.
Read article →Forminator through 1.56.1 trusts forged upload settings and misses dangerous pipe-delimited MIME keys. Update to 1.57.1 and check public upload paths for executable files.
Read article →A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
Read article →A hostile page can rebind its hostname to a Ray dashboard, change Firefox or Safari's User-Agent header, and submit a shell command to the Jobs API.
Read article →Pantheon counted 45 million wp2shell attempts in one week. Defenders should verify current WordPress builds and review exposed sites for persistent access.
Read article →A compromised crates.io account poisoned three Rust packages. Builds ran a downloader; 2,285 arrayref downloads now require cache, lockfile, and host checks.
Read article →CISA now links CVE-2026-45659 to ransomware. Check exact SharePoint builds, then investigate whether low-privilege access reached the farm before patching.
Read article →Public research turns a patched NetScaler memory overflow into a root-code-execution risk for SAML deployments, making build verification urgent.
Read article →CVE-2026-65640 reaches Ghostscript on sites using Imagick; WordPress 7.0.4 and exact backports move content checks ahead of image processing.
Read article →