Skip to content

CVE-2026-94545

CVE

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
September 23, 2026
Last Seen
September 23, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in Next.js, tracked as CVE-2026-94545, allows remote code execution via the ImageResponse feature when attacker-controlled values are included in SVG content. The flaw affects versions 16.2.0 through 16.3.5 and was fixed in version 16.3.6 released on September 22, 2026. Verc...

Public Exploits

Checking GitHub for proof-of-concept code…