logo

45M Weekly Downloads at Risk: Next.js CVE-2026-75604 (CVSS 9.0) Enables Unauthenticated Remote Code Execution

ID: 695c1c1b-9bb4-50a8-80ac-64a699c9771a

STIX ID: report--695c1c1b-9bb4-50a8-80ac-64a699c9771a

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Do Son

...
...

Two critical unauthenticated RCE vulnerabilities in Next.js (a Windows path traversal CVE-2026-75604 and an AVIF/libheif image optimization bug) affect many versions and can lead to full server compromise; Vercel has released patches (upgrade to 15.5.24 or 16.3.3) and advises disabling AVIF optimization until patched, and no active exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.