Critical Next.js RCE Flaw (CVSS 9.0) Affects 45M Weekly Downloads

cyb3rops · x · 2026-08-26

Vercel patched two critical remote code execution (RCE) vulnerabilities in Next.js. CVE-2026-75604 (CVSS 9.0) allows unauthenticated RCE on Windows filesystems, while another (CVSS 9.5) stems from AVIF image optimization. With over 45 million weekly downloads, users are urged to update to versions 15.5.2 or 16.3.3 immediately.

Original post →

More from Infra

Infra channel →