Critical Vulnerabilities in .js Framework Lead to Remote Code Execution Risks
ID: 6cdc1022-b2eb-5aa7-b80a-a52419ac5c71
STIX ID: report--6cdc1022-b2eb-5aa7-b80a-a52419ac5c71
Feed Name: ThreatCluster
Threat Score
Next.js released a critical security update on August 25, 2026 addressing two unauthenticated remote code execution vulnerabilities (CVE-2026-75604 and GHSA-2xp9-vwfh-vxw4) that affect specific Windows-hosted routing configurations and the Image Optimizer's AVIF handling; Cloudflare deployed an emergency WAF mitigation on August 26 and users are urged to upgrade to Next.js 16.3.3 or 15.5.24 as there are no known workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
