{"type":"bundle","id":"bundle--553b12d8-04ce-5ba5-9f35-226544939d5f","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--7b49599e-dec1-5560-9151-96eb6d4ea531","created":"2026-09-20T19:01:22.083Z","modified":"2026-09-20T19:01:22.083Z","name":"Next.js unauth RCE in image optimization on Windows servers","description":"Next.js image optimization on affected configurations (including Windows servers) can allow unauthenticated remote code execution. Upgrade to patched releases.","aliases":["CVE-2026-75604","Next.js image optimization RCE"],"first_seen":"2026-08-25T00:00:00.000Z","last_seen":"2026-08-25T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-75604","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75604"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-75604-nextjs-unauth-rce-image-optimization-windows"},{"source_name":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-75604"}]}]}