CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6028

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

Vercel patched two remote code execution vulnerabilities in Next.js, a React framework for web application development. One flaw, CVE-2026-75604, affects Windows-hosted Next.js applications using Pages and App routers without Cache Component, while the second involves malicious media files and remains unassigned a CVE identifier.

Why it matters: Developers running Next.js applications on Windows must update immediately to prevent remote code execution attacks; teams should patch all affected instances regardless of router configuration to mitigate the media file exploitation vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

Vercel patched two remote code execution vulnerabilities in Next.js, a React framework for web application development. One flaw, CVE-2026-75604, affects Windows-hosted Next.js applications using Pages and App routers without Cache Component, while the second involves malicious media files and remains unassigned a CVE identifier.

Why it matters: Developers running Next.js applications on Windows must update immediately to prevent remote code execution attacks; teams should patch all affected instances regardless of router configuration to mitigate the media file exploitation vector.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

Vercel patched two vulnerabilities in Next.js, a React framework for web application development. CVE-2026-75604, with a CVSS score of 9.0, allows arbitrary code execution on application servers in Windows environments running specific router configurations without cache components. A second vulnerability enabling remote code execution through malicious media files was also fixed but has not yet received a CVE identifier.

Why it matters: Next.js developers using Windows hosting with Pages and App routers need to update immediately to prevent remote code execution attacks targeting their production servers.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary