CyberHighConfirmedDeveloping
9.3
Unpatched Kaltura mwEmbed vulnerabilities enable unauthenticated RCE and file exposure
The Hacker News·2 days ago
Next.js has released security updates addressing two critical vulnerabilities that could allow unauthenticated remote code execution. One flaw specifically impacts Windows-hosted environments, while the other is triggered via AVIF image optimization. No active exploitation has been observed to date.