As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js
Vercel patched two remote code execution vulnerabilities in Next.js, a React framework for web application development. One flaw, CVE-2026-75604, affects Windows-hosted Next.js applications using Pages and App routers without Cache Component, while the second involves malicious media files and remains unassigned a CVE identifier.
Why it matters: Developers running Next.js applications on Windows must update immediately to prevent remote code execution attacks; teams should patch all affected instances regardless of router configuration to mitigate the media file exploitation vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js
Vercel patched two remote code execution vulnerabilities in Next.js, a React framework for web application development. One flaw, CVE-2026-75604, affects Windows-hosted Next.js applications using Pages and App routers without Cache Component, while the second involves malicious media files and remains unassigned a CVE identifier.
Why it matters: Developers running Next.js applications on Windows must update immediately to prevent remote code execution attacks; teams should patch all affected instances regardless of router configuration to mitigate the media file exploitation vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js
Vercel patched two vulnerabilities in Next.js, a React framework for web application development. CVE-2026-75604, with a CVSS score of 9.0, allows arbitrary code execution on application servers in Windows environments running specific router configurations without cache components. A second vulnerability enabling remote code execution through malicious media files was also fixed but has not yet received a CVE identifier.
Why it matters: Next.js developers using Windows hosting with Pages and App routers need to update immediately to prevent remote code execution attacks targeting their production servers.
- Source published
- First seen by Cybersecurity Tracker