Back to all news
Security

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News·August 27, 2026·1 min read
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal is tracked as CVE-2026-75604.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store