Thehackernews
Next.js Vulnerabilities Enable Remote Code Execution Attacks
Article Content
Two critical vulnerabilities in Next.js allow unauthenticated remote code execution (RCE) on Windows-hosted applications using the Image Optimization API for AVIF images. The first flaw, CVE-2026-75604, affects applications using the Pages Router or App Router without Cache Components. Attackers can exploit these vulnerabilities to execute arbitrary code on affected systems. The vulnerabilities have been patched as of August 27, 2026, with developers urged to update their applications immediately. The flaws pose a significant risk to developers and organizations relying on Next.js for web applications. The exact number of affected systems is not specified, but the potential for widespread exploitation is high.
Key Points: • Two critical vulnerabilities in Next.js allow unauthenticated RCE. • CVE-2026-75604 affects applications using Pages or App Router without Cache Components. • Patches were released on August 27, 2026, urging immediate updates.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.