Next.js Rushes Out Fixes for Two Critical Bugs Allowing Remote Takeover
Vercel has released urgent security patches for the Next.js web framework after discovering two critical vulnerabilities that could allow attackers to remotely execute code without needing any login credentials. One flaw can be triggered using a specially crafted AVIF image file, while the second involves a path traversal weakness affecting servers running on Windows filesystems, tracked as CVE-2026-75604.
Next.js is a widely used framework for building websites and web applications, meaning these vulnerabilities could affect many business websites, customer portals, and internal tools built on the platform. Because both flaws allow unauthenticated remote code execution, attackers could potentially take control of vulnerable servers without needing a password or insider access, making these particularly serious risks.
Businesses using Next.js, especially those hosting on Windows-based servers, should treat this as a priority update. Developers or IT providers managing these applications should confirm patch status as soon as possible, since delays leave systems exposed to exploitation attempts that require no prior access.