Security Update: Two critical Next.js vulnerabilities
By Steven Van ·
The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution.
Netlify announced Security Update: Two critical Next.js vulnerabilities on August 25, 2026.
What changed
The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution. Both are patched in 15.5.24 and 16.3.3. Netlify-hosted sites are not affected by the Windows issue, and do not run the Next.js code path affected by the image issue. We still recommend upgrading. Here’s what Netlify customers need to know. Vulnerabilities Vulnerability: CVE-2026-75604 / GHSA-p293-qw3h-jr36 — Unauthenticated remote code execution on Windows-hosted servers Severity: Critical Affected versions: ≥13.4.0 next 15.5.24 or later, or 16.3.3 or later, then redeploy. Resources Next.js August 2026 security release Next.js security advisories
