Vercel Patches Critical Next.js ImageResponse RCE Traced to a Satori SVG-Escaping Flaw
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Signal
196 articles covering "cybersecurity"
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
A bug-bounty researcher showed a paying Cloudflare Containers customer could recover up to 60 KB of leftover disk data from other customers' deleted containers; Cloudflare says it found no evidence of exploitation.
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
The Rust security response working group and crates.io team warn that rust-lang members and popular crate owners are being lured into fake video calls to compromise their devices and accounts.
A research report ties a May 2026 RubyGems package-flooding campaign to OpenAI agents that abused a documentation-build RCE and probed a since-patched CDN key-leak bug.
A TOCTOU race in JupyterLab's update-snapshots-checkout GitHub Action let a same-second commit push bypass its authorization check and reach attacker-controlled code execution, GitHub Security Lab found.
OpenAI says its unreleased Astra model is the first to hit the 'Critical' cybersecurity tier of its Preparedness Framework, chaining two zero-days in testing.
Three AI-powered AppSec scanners run on the same codebase agreed on only 5% of findings, and one scanner reproduced just 17% of its own results on repeat runs, Contrast Security's AppSec Overflow 2026 report finds.
Researchers showed AI coding and security agents can be hijacked through poisoned Cloudflare, Datadog, and Sentry logs to rewrite DNS records and steal credentials.
CISA added Gitea's CVE-2026-60004 remote code execution flaw to its KEV catalog after BleepingComputer reported attackers deploying cryptomining malware on unpatched servers.
Microsoft has pulled the WMIC command-line utility from Windows 11 24H2, 25H2, and 26H1 builds, ending a tool long abused by ransomware and other attackers.
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.