MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 16 h ago, last 16 h ago, peak #11

Payload CMS vulnerability flagged with untrusted redirect flaw

Original: ๐Ÿšจ EUVD-2026-93488 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: next, next, payload (+1 more) ๐Ÿข Vendor: payloadcms, @payloadcms

A medium-severity vulnerability, EUVD-2026-93488, has been catalogued affecting Payload CMS and related Next.js packages, with a CVSS v3.1 score of 6.1 out of 10. The flaw involves an untrusted redirect URL parameter exploit, which could let attackers craft malicious redirects. The advisory was updated on 6 October 2026 and is listed in the EU vulnerability database maintained by ENISA. Administrators running Payload or its Next.js integrations are advised to review the advisory and check for patches.

Why now: Security teams monitoring the EU vulnerability database are flagging a newly updated medium-severity flaw affecting widely used Payload CMS packages.

Payload CMSENISANext.js

Open on mastodon โ†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1264924