Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Next.js CVE-2026-94545: Critical ImageResponse Vulnerability Enables RCE via SVG

A critical remote code execution vulnerability was disclosed in Next.js on September 22, 2026, and an out-of-band security update was released to fix it. CVE-2026-94545 is a remote code execution vulnerability in next/og, the feature Next.js applications use to generate images on demand. The GitHub advisory rates it 9.5 on CVSS v4.0. An unauthenticated attacker can reach it over the network, and the root cause is an upstream SVG-escaping vulnerability that applications inherit without realizing it.

WordPress CVE-2026-87902: Unauthenticated RCE Exploited Within Hours

WordPress patched CVE-2026-87902 on September 22, 2026. Attackers were exploiting it the same day. Within hours of disclosure, attackers progressed from reconnaissance to active exploitation attempts, including attempts to write malicious PHP files to disk. The vulnerability is critical, with a CVSS v4.0 score of 9.2. Unauthenticated attackers can exploit it remotely. A public scanning template is already in circulation, and CISA has added the vulnerability to its KEV catalog.