August 2026 Security Release: Two Critical RCEs Patched
By BIOS Founding Team

Next.js confirmed the previously flagged 'advance notice' security release actually shipped, moved forward a day after a second critical vulnerability was identified. Versions 16.3.3 and 15.5.24 addressed two critical-severity, unauthenticated remote-code-execution vulnerabilities.
The first, tied to an upstream AVIF-decoding flaw, affects the Image Optimization API. The second affects Windows-hosted servers using both the Pages Router and App Router without Cache Components, with no known workaround for affected Windows deployments; Linux and macOS are unaffected. All users on 15.5.x or 16.3.x are urged to upgrade immediately.
Full details: https://nextjs.org/blog/august-2026-security-release
More from the community

Stable and Longterm Kernel Updates: 7.2.4, 6.18.50, 6.12.109
Greg Kroah-Hartman pushed out new stable and longterm point releases across the 7.2, 6.18, and 6.12 lines, each bundling accumulated fixes across drivers, filesystems, and core subsystems.

Rust Debugging Survey 2026 Results
The Rust Project published results from its 2026 debugging survey, gathering community feedback on debugging tools and workflows to guide future tooling investment.

Docker Desktop 4.90.0
This release made 'Ask Gordon,' Docker's AI assistant, accessible as a persistent right-side drawer and added one-click AI diagnosis for containers, images, and volumes with detected issues.