Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaws in Next.js Allow Remote Code Execution

Critical Flaws in Next.js Allow Remote Code Execution

Posted on August 27, 2026 By CWS

Vercel has issued important security updates addressing two critical vulnerabilities in the Next.js framework. These flaws allow unauthorized remote code execution, posing significant risks if not promptly mitigated. The vulnerabilities stem from an AVIF image processing issue and a path traversal flaw affecting Windows-based servers.

Windows Path Traversal Vulnerability

The path traversal issue, identified as CVE-2026-75604 with a CVSS score of 9.0, impacts Next.js applications using both the Pages Router and App Router on Windows servers that lack Cache Components. The flaw does not affect Linux or macOS deployments. Vercel advises immediate upgrades for Windows-hosted applications as no workarounds exist.

Updates are available in Next.js 15.5.24 (Maintenance LTS) and 16.3.3 (Active LTS), released on August 25, 2026. Users can upgrade via npm commands to ensure their systems are secure. Notably, Vercel-hosted applications automatically receive protection from these vulnerabilities without needing upgrades.

AVIF Image Processing Flaw

The second vulnerability pertains to the AVIF image processing functionality in Next.js, using the sharp package dependent on the libheif library. A critical heap buffer overflow in libheif can trigger remote code execution when processing malicious AVIF images. This flaw, tracked under GHSA-2xp9-vwfh-vxw4, affects Next.js versions 10.0.0 through 15.5.23 and all 16.x versions up to 16.3.2.

Libheif’s vulnerability lies in the image scaling code, where a crafted AVIF file can cause buffer overflow, leading to potential exploitation. The patch disables AVIF optimization in Next.js until a fix from libheif is implemented. Researchers rootxharsh and KarimPwnz provided a proof-of-concept for this vulnerability.

Ongoing Security Measures

Vercel’s swift response, including moving the patch release forward by a day due to an additional critical vulnerability, underscores their commitment to security. This August update, part of Vercel’s monthly security cadence initiated in July 2026, is the second formal release, following a July update that addressed nine vulnerabilities.

Despite the recent surge in security disclosures for Next.js, including the React2Shell deserialization flaw in December 2025, no exploits of the August vulnerabilities have been reported as of August 27, 2026. Vercel’s proactive measures, alongside ongoing vulnerability research, aim to fortify the Next.js framework against emerging threats.

The Hacker News Tags:AVIF flaw, CVE-2026-75604, heap buffer overflow, image processing, libheif, Next.js, remote code execution, Security, software patch, Vercel, web framework, Windows vulnerability

Post navigation

Previous Post: How Stolen AWS Credentials Can Lead to Major Security Breaches
Next Post: AI Security’s Future Hinges on Comprehensive Data

Related Posts

Taiwan Web Servers Breached by UAT-7237 Using Customized Open-Source Hacking Tools Taiwan Web Servers Breached by UAT-7237 Using Customized Open-Source Hacking Tools The Hacker News
Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More The Hacker News
China-Linked JDY Botnet Expands to Over 1,500 Devices China-Linked JDY Botnet Expands to Over 1,500 Devices The Hacker News
UAT-9921 Targets Tech and Finance with VoidLink Malware UAT-9921 Targets Tech and Finance with VoidLink Malware The Hacker News
Kali365 Exploits Microsoft Login to Threaten US Firms Kali365 Exploits Microsoft Login to Threaten US Firms The Hacker News
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • IoT Botnet and Water Systems Under Cyber Threats
  • CISA Alerts on Citrix NetScaler Security Flaw Exploitation
  • AI Security’s Future Hinges on Comprehensive Data
  • Critical Flaws in Next.js Allow Remote Code Execution
  • How Stolen AWS Credentials Can Lead to Major Security Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • IoT Botnet and Water Systems Under Cyber Threats
  • CISA Alerts on Citrix NetScaler Security Flaw Exploitation
  • AI Security’s Future Hinges on Comprehensive Data
  • Critical Flaws in Next.js Allow Remote Code Execution
  • How Stolen AWS Credentials Can Lead to Major Security Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark