Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Source: The Hacker News Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting s Read original

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Source: The Hacker News Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting s Read original

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday Source: BleepingComputer CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. […] Read original

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers target Microsoft SharePoint RCE chain with PoC exploit Source: BleepingComputer Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. […] Read original

August 26, 2026 Updated: October 8, 2026 1 min

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original