Next.js released security fixes for critical flaws that could let attackers run malicious code on vulnerable servers without logging in. The issues include an AVIF image-processing vulnerability and a Windows-specific flaw affecting Next.js deployments; the article says the bugs can lead to unauthenticated remote code execution and were patched by the framework maintainers in updated releases. Organizations using affected Next.js versions should review the vendor advisory for exact patched versions and exposure conditions.
Why it matters: Next.js is widely used to build web applications, so a critical remote-code-execution bug can put public-facing services at immediate risk. Teams running Next.js should identify affected deployments and update quickly, especially internet-exposed or Windows-based environments.
info@thehackernews.com (The Hacker News)
2026.08.27
100% relevant
This article appears to be the initial tracked report here about Next.js issuing patches for these specific critical AVIF and Windows remote-code-execution flaws.
← Back to all stories