logo

React2Shell2? – CVE-2026-75604 – Next.JS Pre-Auth RCE on Windows Servers

ID: 43066c4d-0378-5ccd-8f4e-e5fdf65499ca

STIX ID: report--43066c4d-0378-5ccd-8f4e-e5fdf65499ca

Feed Name: Checkmarx Zero

Threat Score
78/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Dor Tumarkin

...
...

A critical pre-auth vulnerability in Next.js (CVSS 9.0) stemming from improper backslash validation on Windows was disclosed; proof-of-concept exploit code is already appearing. Patch to Next.js 15.5.24 or 16.3.3 (and other listed canary/stable releases) immediately; an additional libheif/AVIF image-optimization issue was also fixed and AVIF optimization disabled in the update. Checkmarx SCA detects the affected versions and will flag them in scans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.