Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
CVE-2026-47731 is an unreviewed GitHub advisory describing a path traversal vulnerability in the AMMOS Instrument Toolkit that allows arbitrary file append over…
Security researchers at Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit.…
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to…
Security researchers have demonstrated a new attack technique that abuses Windows Plug and Play (PnP) auto-install to achieve full SYSTEM privileges on…
Cisco has released security updates to address 12 vulnerabilities affecting Catalyst SD-WAN and IOS XE Software, including three with a CVSS score…
CVE-2026-20273 is a high-severity vulnerability in Cisco IOS XE Software with a CVSS score of 8.6. It is caused by improper input…
CVE-2026-48374 is a high-severity vulnerability in Adobe Bridge with a CVSS score of 7.8. It is a path traversal issue that could…
cgi-io is a CGI component in OpenWrt for file I/O operations. It is affected by CVE-2026-62947, a path traversal vulnerability that can…
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…