Find notable cyber news and cases, enriched with sources, timelines, and signals.

Vercel security patch release for CVE-2026-75604

Security Patch Release
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixes landed in Next.js 15.5.24 and 16.3.3, covering both a Windows path traversal issue and a flaw reachable through crafted AVIF image files. The Windows bug is tracked as CVE-2026-75604 and affects Next.js 13.4 through 15.5.23 plus 16.0 through 16.3.2. Vercel-hosted apps are reported protected, while affected Windows-hosted users were told to upgrade immediately.

Related Happenings

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
H score43 First: 27.08.2026 00:33 Last: 27.08.2026 00:33 Sources 1

About this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Adobe security patch release for CVE-2026-71398

Security Patch Release
H score37 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...

Latest development: 12.08.2026 14:13

Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.

WordPress security patch release for CVE-2026-64638

Security Patch Release
H score34 First: 07.08.2026 15:56 Last: 07.08.2026 15:56 Sources 1

About this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...

Timeline

  1. 27.08.2026 18:13 1 articles · 4h ago

    Vercel advances its August Next.js security release

    Initial Disclosure

    Vercel moved its August patch window forward by one day after identifying an additional critical-severity vulnerability in an upstream dependency, and the company said the release now covered two critical Next.js flaws that can lead to unauthenticated remote code execution, including CVE-2026-75604 on Windows-hosted applications.

    Show sources
  2. 27.08.2026 18:13 2 articles · 4h ago

    Vercel publishes Next.js 15.5.24 and 16.3.3

    Mitigation Patch Update

    Vercel released Next.js 15.5.24 and 16.3.3 on August 25, 2026 to fix the AVIF-image remote code execution flaw and the Windows path traversal bug, told affected Windows-hosted operators to upgrade immediately, and said Vercel-hosted applications are protected without requiring an upgrade.

    Show sources
  3. 27.08.2026 18:13 1 articles · 4h ago

    AVIF optimization flaw in Next.js remains gated on libheif remediation

    Technical Analysis Update

    The AVIF issue in Next.js depends on image/avif being enabled in next.config.js and flows through sharp and libheif, where researchers said they were able to get RCE on multiple applications; by August 27, 2026, no exploitation of either August vulnerability had been reported, and the patched Next.js releases disabled AVIF optimization until an upstream libheif fix is available.

    Show sources