CRITICAL
Next.js Patches Critical AVIF and Windows Path Traversal Flaws Enabling Unauthenticated RCE
Vercel has released patches for two critical-severity vulnerabilities in the Next.js web framework, both allowing unauthenticated remote code execution. One is exploitable via specially crafted AVIF image files; the other is a path traversal flaw, tracked as CVE-2026-75604, affecting servers that run on a Windows filesystem.
Teams running Next.js in production, particularly on Windows hosts, should update immediately. No confirmation of in-the-wild exploitation was included in the source summary.