Next.js Critical Security Updates for August 2026
Next.js versions 15.5.24 and 16.3.3 address critical vulnerabilities including a Windows path traversal (CVE-2026-75604) and an AVIF image processing heap overflow. Users…
Cybersecurity products, tools, platforms and software categories.
Next.js versions 15.5.24 and 16.3.3 address critical vulnerabilities including a Windows path traversal (CVE-2026-75604) and an AVIF image processing heap overflow. Users…
libheif versions through v1.23.1 contain a critical heap buffer overflow in image scaling code, exploitable via crafted AVIF files. The flaw can…
Next.js uses the sharp image processing package, which relies on libheif for AVIF parsing. The critical libheif heap buffer overflow can be…
Anthropic Claude Code has been affected by multiple vulnerabilities, including CVE-2026-35603 and CVE-2026-25725, which allow command execution and sandbox escape.
NVIDIA NemoClaw has a vulnerability (CVE-2026-65105) that lets attackers control the local Ollama model server via a malicious web page.
Kiro Powers, a feature in Amazon Kiro that bundles MCP server configurations, steering files, and hooks, was exploited in a prompt injection…
A vulnerability chain in OpenAI Codex CLI for Windows abuses prompt injection through web.run to execute host-level commands outside the sandbox.
Amazon Kiro, an AI-powered agentic IDE, was found vulnerable to prompt injection attacks that could exfiltrate sensitive data through Kiro Powers. The…
Prophet AI investigates every alert at every severity, plans investigations dynamically, queries SIEM, EDR, identity, cloud, and email tools, and provides an…
Prophet AI Threat Hunter runs expert-curated and scheduled hunts against a live profile of the organization and its coverage gaps, helping teams…