Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Next.js CVE-2026-94545: Critical ImageResponse Vulnerability Enables RCE via SVG

A critical remote code execution vulnerability was disclosed in Next.js on September 22, 2026, and an out-of-band security update was released to fix it. CVE-2026-94545 is a remote code execution vulnerability in next/og, the feature Next.js applications use to generate images on demand. The GitHub advisory rates it 9.5 on CVSS v4.0. An unauthenticated attacker can reach it over the network, and the root cause is an upstream SVG-escaping vulnerability that applications inherit without realizing it.

WordPress CVE-2026-87902: Unauthenticated RCE Exploited Within Hours

WordPress patched CVE-2026-87902 on September 22, 2026. Attackers were exploiting it the same day. Within hours of disclosure, attackers progressed from reconnaissance to active exploitation attempts, including attempts to write malicious PHP files to disk. The vulnerability is critical, with a CVSS v4.0 score of 9.2. Unauthenticated attackers can exploit it remotely. A public scanning template is already in circulation, and CISA has added the vulnerability to its KEV catalog.

CVE-2026-67401: SQL Injection in cPanel's EmailTrack Puts Shared Hosting Environments at Risk

A critical SQL injection vulnerability has been identified in cPanel & WHM’s EmailTrack functionality. The vulnerability was disclosed by cPanel on September 8, 2026, affecting every supported release line. It allows an authenticated cPanel account holder with mail related privileges to ultimately achieve root-level code execution on the underlying host.

AppTrana Adds Post-Quantum Cryptography Support with X25519MLKEM768

Quantum computers could very soon undermine the public-key cryptography that secures financial transactions, health records, and other sensitive data moving over TLS today. When that happens, encrypted information protected by vulnerable cryptography could become accessible. Encrypted traffic can be intercepted and stored today, with the expectation that it will be decrypted once a sufficiently capable quantum computer exists.

Indusface WAS AI-Assisted Pentest: Comprehensive Vulnerability Assessment Across Web, API and AI Apps

For years, our security team has run pentests against business-critical applications across industries, and one pattern stands out. The vulnerabilities that are the most difficult to remediate are business logic vulnerabilities: IDOR, broken access control, privilege escalation, and multi-step workflow abuse. These are the kind of vulnerabilities pentest experts find by noticing a broken assumption behind one API call and chasing it until the full exploit path becomes clear.

CVE-2026-0768: Critical RCE in Langflow AI Agent Builder

A critical remote code execution vulnerability has been identified in Langflow. The vulnerability was first reported to the vendor in mid-2025 and disclosed publicly as a zero-day in January 2026. Exploitation attempts rose sharply in late August 2026, moving from isolated probing to continuous, multi-source scanning within days.

SharePoint CVE-2026-55040 Actively Exploited: AI-Discovered RCE Chain

CVE-2026-55040, a critical SharePoint authentication bypass, is now being actively exploited. A proof-of-concept went public on August 11. Within 24 hours, threat intelligence firm Defused confirmed exploitation attempts against its SharePoint honeypots using that same PoC. Over 8,500 SharePoint servers remain reachable from the open internet, putting unpatched instances at immediate risk.

CVE-2026-58048: cPanel & WHM Database Privilege Escalation Vulnerability

Hosting environments run on a basic assumption: an account with limited permissions should stay limited. CVE-2026-58048 breaks that assumption inside cPanel & WHM. Any authenticated account with MySQL or MariaDB feature access, including a standard low-privilege hosting account, can now escalate to root-level database privileges through a database rename operation. A public proof-of-concept already exists, which means the barrier to exploitation is low and the window to act is short.

SwyftComply AI: How We Turn Vulnerability Flood Into Audit-Ready Protection

For the last several months, we have run AI agents against real production applications across industries. Two questions drove the work: what does AI-powered vulnerability analysis and pentesting surface at scale, and what does protection have to look like to keep pace. The vulnerability discovery side confirmed what Mythos made impossible to ignore.

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft's July 2026 Advisory

AI assistants are quietly becoming one of Microsoft’s largest attack surfaces. In its July 2026 advisory, Microsoft patched a command injection vulnerability in Copilot. Crafted prompts can trigger unintended actions through this flaw. The advisory also included a critical SSRF vulnerability in Entra’s identity provisioning service. It carries the among the highest severity score in the entire release. Both point to the same shift.