Skip to main content

Security Update: Two critical Next.js vulnerabilities

By Steven Van ·

The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution.

Netlify announced Security Update: Two critical Next.js vulnerabilities on August 25, 2026.

What changed

The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution. Both are patched in 15.5.24 and 16.3.3. Netlify-hosted sites are not affected by the Windows issue, and do not run the Next.js code path affected by the image issue. We still recommend upgrading. Here’s what Netlify customers need to know. Vulnerabilities Vulnerability: CVE-2026-75604 / GHSA-p293-qw3h-jr36 — Unauthenticated remote code execution on Windows-hosted servers Severity: Critical Affected versions: ≥13.4.0 next 15.5.24 or later, or 16.3.3 or later, then redeploy. Resources Next.js August 2026 security release Next.js security advisories

Netlify
Netlify
Lightning-fast web platform for deploying, hosting, and scaling modern sites — one-click deploys from Git or any modern AI builder.
View Netlify →

Read the original announcement →

Read Security Update: Two critical Next.js vulnerabilities on Creators Toolbox