[NEW] [high] Vercel Next.js: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Vercel Next.js to manipulate data, disclose information, conduct a denial of service attack, and bypass security measures.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit multiple vulnerabilities in Vercel Next.js to manipulate data, disclose information, conduct a denial of service attack, and bypass security measures.
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle Communications to compromise confidentiality, integrity, and availability.
An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, cause a denial-of-service attack, disclose confidential information, bypass security measures, or carry out other unspecified attacks.
An attacker can exploit multiple vulnerabilities in Google Chrome to carry out an unspecified attack. Possible impacts include memory corruption, execution of arbitrary code, manipulation or disclosure of data, and triggering a denial-of-service state.
A remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files.
An attacker can exploit multiple vulnerabilities in FasterXML Jackson to manipulate data and bypass security measures.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in patch to carry out a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in FreeType to disclose information.
An attacker can exploit multiple vulnerabilities in Roundcube to bypass security measures, cause denial-of-service attacks, perform cross-site scripting attacks, and manipulate or disclose data.
A remote, anonymous attacker can exploit a vulnerability in GStreamer to bypass security measures.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in libxml2 to conduct a Denial of Service attack.
A local attacker can exploit multiple vulnerabilities in gzip to manipulate files and disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in 7-Zip to bypass security measures and manipulate data.
A remote, anonymous attacker can exploit a vulnerability in nghttp2 to manipulate data.
An attacker can exploit multiple vulnerabilities in Mattermost Server to manipulate data, bypass security measures, or conduct other unspecified attacks.
A remote, anonymous attacker can exploit multiple vulnerabilities in libssh2 to manipulate files, cause memory corruption, trigger a denial-of-service condition, or achieve other unspecified impacts.
A remote, anonymous attacker can exploit a vulnerability in jq to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in vBulletin to execute arbitrary program code.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Drivers c…
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Seve…
A remote, anonymous attacker can exploit a vulnerability in Zabbix to conduct a cross-site scripting attack.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Severa…
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A …
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Severa…
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - Cryptographic API; - InfiniBand drivers; - IOMMU subsystem; - Network drive…
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities.
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities.
An attacker can exploit multiple vulnerabilities in Fortinet FortiOS to bypass security measures, disclose information, or execute code.
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities.
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in denial of service, domain takeover, information disclosure or privilege escalation. https://security-tracker.debian.org/tracker/DSA-6401-1
Multiple vulnerabilities have been discovered in Apple products. Some of them allow an attacker to cause arbitrary code execution, privilege escalation, and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in Samba. Some of them allow an attacker to cause a remote denial of service, a breach of data confidentiality, and a bypass of the security policy.
Two vulnerabilities were discovered in hplip, the HP Linux Printing and Imaging System, which may result in privilege escalation or arbitrary code execution. https://security-tracker.debian.org/tracker/DSA-6402-1
Serial Number: AV26-750 Date: July 27, 2026 As of July 27, 2026, Erlang is affected by vulnerabilities in the following product: OTP 10.2 Prior to 11.7.4 6.0 Prior to 17.0.4 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessa…
Serial number: AV26-109 Date: February 10, 2026 Updated: July 27, 2026 On February 10, 2026, Fortinet published security advisories to address vulnerabilities in the following products: FortiAuthenticator 6.6 – versions 6.6.0 to 6.6.6 FortiAuthenticator 6.5 – all versions FortiAu…
Serial number: AV26-748 Date: July 27, 2026 As of July 25, 2026, Redis is affected by a vulnerability in the following product: Redis Versions prior to 8.8.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as t…
Serial Number: AV26-747 Date: July 27 2026 Microsoft security advisory (AV26-747) As of July 26, 2026, Microsoft is affected by vulnerabilities in the following product: Microsoft Edge (Chromium-based) Prior to 150.0.4078.99 The Cyber Centre encourages users and administrators to…
Impact It's possible to forge a request to delete a message. Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. Workarounds There's no easy workaround except upgrading. References https://jira.xwiki.org/browse/DISCUSSION-22 For more information …
Zhihan Zheng discovered that FreeIPMI had several buffer overflow vulnerabilities in ipmi-oem response message handling. A local attacker with control a malicious IPMI device or simulator could possibly cause FreeIPMI to crash, resulting in a denial of service. (CVE-2026-33554, C…
It was discovered that Roc Toolkit incorrectly handled WAV files with a malformed "smpl" chunk. An attacker could use this issue to cause Roc Toolkit to crash, resulting in a denial of service, or possibly execute arbitrary code.
It was discovered that the GNU C Library iconv function incorrectly handled certain IBM character sets. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-4046) It was discovered that the GNU C Library DNS functions incorrectly handled certain DNS s…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchest…
An attacker can exploit multiple vulnerabilities in Vaultwarden to bypass security measures, conduct a denial of service attack, and disclose information.