logo

Next.js moves to scheduled security releases

ID: 853c7f5f-42cf-5d65-af17-31bb9cb174c7

STIX ID: report--853c7f5f-42cf-5d65-af17-31bb9cb174c7

Feed Name: Socket Blog

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Sarah Gooding

...
...

Vercel is instituting a monthly, pre-announced security release program for Next.js after a series of high-severity issues — notably React2Shell (CVE-2025-55182), a CVSS 10.0 pre-auth RCE that was actively exploited at scale, and a CVSS 9.1 authorization bypass — exposed hundreds of thousands of instances and attracted both opportunistic criminals and state-affiliated actors; the scheduled cadence aims to improve patch planning, partner mitigation (WAF rules, hosting protections), and coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.