Next.js, MikroTik, React Router Vulnerabilities Disclosed
Next.js, MikroTik, and React Router face multiple vulnerabilities, alongside critical flaws in VMware and OpenShift.

MikroTik RouterOS API authentication is vulnerable to excessive login attempts due to a lack of effective rate-limiting, account lockout, or source-based restrictions, potentially allowing attackers to compromise devices. This impacts numerous network devices globally, as noted by CISA. CVE-2026-16347.
A wave of nine vulnerabilities in Vercel's Next.js framework could allow attackers to perform server-side request forgery (SSRF), bypass authentication, or cause denial-of-service conditions. These flaws affect various Next.js features, including Server Actions and image optimization, and have been patched by Vercel. As reported by Cyber Security News, these vulnerabilities could lead to significant compromise for applications built with Next.js. CVE-2026-64641, CVE-2026-64642, CVE-2026-64644, CVE-2026-64645, CVE-2026-64646, CVE-2026-64648, CVE-2026-64649.
Multiple vulnerabilities have been disclosed in React Router, including open redirects and cross-site scripting (XSS) flaws. These issues stem from improper handling of redirects and could allow attackers to trick users into visiting malicious sites or execute arbitrary scripts in their browsers. The vulnerabilities have been addressed in updated versions of React Router. CVE-2026-53667, CVE-2026-53668.
A critical SQL injection vulnerability in VMware's VeloCloud Orchestrator allows authenticated attackers to exfiltrate sensitive data by crafting malicious SQL queries. This blind SQL injection flaw requires tenant-level access but could lead to significant data breaches for organizations using the VeloCloud platform. CVE-2020-3973.
OpenShift's oauth-proxy is susceptible to header smuggling, enabling identity impersonation on WSGI/PHP upstreams. This vulnerability could allow an attacker to gain unauthorized access by impersonating legitimate users. CVE-2026-49332.
Several denial-of-service vulnerabilities have been identified in the ninenines cowboy and cowlib libraries. These flaws involve unbounded decoding of HPACK/QPACK prefixed integers and duplicate HTTP/1.1 header names, which could be exploited to crash services. CVE-2026-59248, CVE-2026-65624.
A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows an unauthenticated attacker on the local network to cause a denial-of-service by exhausting memory resources through high-volume multicast traffic. CVE-2026-54429.
Red Hat's dogtag-pki has an authentication bypass vulnerability in its ACME admin endpoint, which can be exploited via a trailing slash. This flaw allows unauthorized administrative actions on PKI instances. CVE-2026-18047.