CVE-2026-108693 lets an attacker run code on Windows by planting a fake gswin64c.exe that ImageMagick launches by bare name when Ghostscript is unregistered. VulnCheck, the CNA, rates it 7.0 (CVSS 3.1); NVD has not scored it yet. No fixed version is named.

When Ghostscript is not registered on the system, ImageMagick's NTGhostscriptEXE() function launches gswin64c.exe by bare name instead of a full path.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
The WPO365 WordPress plugin has patched two high-severity vulnerabilities in versions through 44.1. Both flaws could allow unauthenticated attackers to achieve site takeover or persistent script injection.
Winsiderss System Informer versions through 4.0.26241.138 contain an incorrect authorization flaw that lets local attackers execute code as SYSTEM from any signed process. Vulncheck rates the issue 7.8 and 8.5.
Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.
PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.
IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.