Threat Intelligence

Next.js Rushes Out Fixes for Two Critical Bugs Allowing Remote Takeover

The Hacker News · 28 Aug 2026
Key Takeaway If your website or app runs on Next.js, update to the latest patched version immediately, particularly if it's hosted on a Windows server.

Vercel has released urgent security patches for the Next.js web framework after discovering two critical vulnerabilities that could allow attackers to remotely execute code without needing any login credentials. One flaw can be triggered using a specially crafted AVIF image file, while the second involves a path traversal weakness affecting servers running on Windows filesystems, tracked as CVE-2026-75604.

Next.js is a widely used framework for building websites and web applications, meaning these vulnerabilities could affect many business websites, customer portals, and internal tools built on the platform. Because both flaws allow unauthenticated remote code execution, attackers could potentially take control of vulnerable servers without needing a password or insider access, making these particularly serious risks.

Businesses using Next.js, especially those hosting on Windows-based servers, should treat this as a priority update. Developers or IT providers managing these applications should confirm patch status as soon as possible, since delays leave systems exposed to exploitation attempts that require no prior access.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.