Critical Next.js RCE Flaw (CVSS 9.0) Affects 45M Weekly Downloads
cyb3rops · x · 2026-08-26
Vercel patched two critical remote code execution (RCE) vulnerabilities in Next.js. CVE-2026-75604 (CVSS 9.0) allows unauthenticated RCE on Windows filesystems, while another (CVSS 9.5) stems from AVIF image optimization. With over 45 million weekly downloads, users are urged to update to versions 15.5.2 or 16.3.3 immediately.
More from Infra
- Linux Foundation Celebrates 35th Anniversary, Open Source Targets AI — 0xsachi · 2026-08-26
- Open Source Facefusion Android App Runs Video Face Swap on Snapdragon NPU — Few_Caregiver8134 · 2026-08-26
- Apple M5 Mac Studio page features LM Studio for local AI — mattturck · 2026-08-26
- Chinese chip packaging firms invest $2.2B in expansion fueled by AI boom — pstAsiatech · 2026-08-26
- Can I run MiniMax H3 locally on an RTX 2060 with 6GB VRAM? — Amjad_K · 2026-08-26
- a16z Partner: Distinction between training and inference will become meaningless — Kyrannio · 2026-08-26