45M Weekly Downloads at Risk: Next.js CVE-2026-75604 (CVSS 9.0) Enables Unauthenticated Remote Code Execution
ID: 695c1c1b-9bb4-50a8-80ac-64a699c9771a
STIX ID: report--695c1c1b-9bb4-50a8-80ac-64a699c9771a
Feed Name: securityonline.info
Threat Score
Two critical unauthenticated RCE vulnerabilities in Next.js (a Windows path traversal CVE-2026-75604 and an AVIF/libheif image optimization bug) affect many versions and can lead to full server compromise; Vercel has released patches (upgrade to 15.5.24 or 16.3.3) and advises disabling AVIF optimization until patched, and no active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
