Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has patched two critical unauthenticated remote code execution vulnerabilities in Next.js: one exploitable through maliciously crafted AVIF image files and another via Windows path traversal. Both flaws pose significant risk to unpatched deployments, as they can be triggered without authentication and enable full code execution on affected servers.
Rockwell Automation OTTO Fleet Manager versions 2.36.2 and earlier contain a weak password hashing vulnerability (CVE-2026-75112) that uses insufficient computational effort in its bcrypt implementation, making offline brute-force attacks against stored password hashes significantly easier if an attacker obtains an unencrypted system backup. The vulnerability carries a CVSS score of 6.8 and affects critical infrastructure in manufacturing and transportation sectors worldwide. Rockwell Automation has released version 2.36.3 to address the issue and recommends users enable encrypted system backup as documented in security advisory SD1791.
CISA has disclosed three critical vulnerabilities in Xiiaozet LK100W devices running versions prior to 2.1.240, including OS command injection, missing authentication for critical functions, and authentication bypass flaws that could allow complete device compromise. All three vulnerabilities carry CVSS scores of 9.8 or higher and affect the device's web-based management interface, with Xiiaozet recommending immediate updates to version 2.1.240 as mitigation.
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-49105 (ownCloud authentication flaw), CVE-2026-53362 (Linux kernel vulnerability), and CVE-2026-66384 (JFrog Artifactory path traversal issue). Federal agencies are required under BOD 26-04 to prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities not yet listed can submit nominations to CISA for potential catalog inclusion.
CISA has published an advisory detailing 13 vulnerabilities affecting Ebyte NA111-M gateway devices running Firmware 9013-2-17, with multiple critical flaws rated up to CVSS 9.8 that could allow complete device compromise through missing authentication, weak cryptographic practices, and cleartext transmission of sensitive data. The vulnerabilities span authentication bypass, CSRF, insufficient rate limiting, privilege escalation, and credential exposure across both the web management interface and MQTT communications. Ebyte acknowledged the vulnerabilities and indicated patch development, but has not responded to follow-up coordination requests and no patch availability has been announced to CISA.