BoletimSecAugust 27, 2026🇵🇹Translated from Portuguese

Next.js Patches Two Critical RCE Vulnerabilities in Versions 15.5.24 and 16.3.3

Next.js has received a security update to fix two critical vulnerabilities that can lead to remote code execution without authentication. The patches were made available in versions 15.5.24 and 16.3.3.

The first flaw, CVE-2026-75604, received a CVSS score of 9.0 and affects applications hosted on Windows servers that use Pages Router or App Router without Cache Components. The issue is related to path traversal. An attacker can manipulate paths processed by the application and, under specific conditions, achieve code execution on the server without requiring credentials or user interaction. Vulnerable versions include those from 13.4 up to but not including 15.5.24, as well as the 16.0 line up to but not including 16.3.3. There is no workaround for affected Windows servers.

The second vulnerability targets the Image Optimization API when AVIF files are processed. A specially crafted malicious AVIF file can exploit the image processing pipeline and result in code execution. This flaw affects versions from 10.0.0 up to releases prior to 15.5.24, plus versions 16 prior to 16.3.3.

Administrators should update dependencies, rebuild containers, and confirm that production environments run Next.js 15.5.24 or 16.3.3 or later, with priority given to Windows servers and applications that process user-submitted images.

Related articles

HispasecVulnerabilities & Exploits

CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws

On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling confirmed active exploitation and requiring immediate remediation priority. The batch includes a recent memory corruption issue in Citrix NetScaler ADC and NetScaler Gateway tracked as CVE-2026-8452, along with five older flaws affecting Microsoft SQL Server, the Linux kernel, Ajax.NET Professional, Red Hat libuser, and Red Hat ABRT. Citrix released patches for the NetScaler vulnerability on June 30, 2026, while CISA set an August 29, 2026 deadline for federal agencies. Real-world attacks have already deployed web shells and performed reconnaissance after successful exploitation of the Citrix appliance. The remaining CVEs enable remote code execution, local privilege escalation, and denial-of-service conditions across widely deployed enterprise technologies.

Security NEXTVulnerabilities & Exploits

Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA

Apache Tomcat has received updates addressing 11 vulnerabilities across versions 11.0.25, 10.1.59, and 9.0.121. The Apache Software Foundation rated four issues as Important, while CISA assigned Critical severity to four CVEs based on CVSS v3.1 scores reaching 9.8. The flaws include authentication bypasses, access control evasion due to path evaluation order, off-by-one errors, and HTTP/2 resource leaks leading to denial of service. One vulnerability was disclosed earlier in July, with the remaining ten detailed on August 25. Moderate and Low severity issues were also patched in the same releases. The discrepancies in severity ratings between the vendor and CISA highlight differing risk assessments for the same CVEs.

BoletimSecVulnerabilities & Exploits

SonicWall Patches Critical Path Traversal and Update Flaws in NetExtender for Linux

SonicWall has released fixes for two high-severity vulnerabilities in its NetExtender client for Linux that could allow remote attackers to write arbitrary files with root privileges and manipulate the automatic update process. The flaws impact versions 10.3.5 and earlier, while the Windows version remains unaffected. CVE-2026-66152 carries a CVSS score of 8.8 and stems from improper handling of tar archives containing OPSWAT data, enabling path traversal that lets attackers escape the intended extraction directory. CVE-2026-66153 scores 7.0 and arises from inadequate symlink and temporary file handling in the NEService update mechanism. Both issues require user interaction to exploit, and no in-the-wild attacks have been observed so far. Administrators are urged to upgrade immediately to version 10.3.6 or later, as no workarounds exist.

安全客Vulnerabilities & Exploits

Redis Patch Bypass Enables Multiple RCE Exploits as PoCs for TLS and Stream Vulnerabilities Go Public

Multiple remote code execution vulnerabilities have been disclosed in Redis over the past month, including a critical patch bypass for CVE-2026-25243 that reintroduces Double Free flaws via crafted stream operations. The latest issue, QVD-2026-58458 affecting the TLS pending list, now has full technical details and a working PoC available, following the earlier QVD-2026-55651 disclosure. All three flaws impact nearly every production version still in use, from Redis 6.2.22 and below through 7.4.9 and 8.6.4. Although authentication is required, widespread weak or empty password configurations and exposed instances make exploitation trivial for attackers. Successful compromise grants arbitrary code execution in the Redis process context, enabling standard post-exploitation steps such as credential harvesting and lateral movement across internal networks. Organizations are urged to inventory all instances, apply the latest patches immediately, restrict network access via ACLs, and monitor for anomalous use of commands like XGROUP, EVAL, and RESTORE.