Home » TUTORIALS & GUIDES » Web Development & Website » Next.js Security Vulnerability: Check Your Site Now

Next.js Security Vulnerability: Check Your Site Now

A major new security vulnerability has been discovered in Next.js. It's crucial to check and update your website without delay to prevent any compromise.

A CVSS score of 9.0 is the kind of number that should make any SME leader jump. If your website or application runs on Next.js, the question is no longer “should we check” but “how long has it been since you last checked.” Between May, September, and October 2026, Vercel released several critical patches for this framework, and some sites remain exposed without anyone realizing it. Here’s how to assess where you stand and what to do within the next few hours.

The most critical Next.js security vulnerability of 2026, referenced as CVE-2026-75604, carries a CVSS score of 9.0 according to CERT Santé. It affects versions 13.4.0 to 15.5.23 and 16.0.0 to 16.3.2, enabling remote code execution. The fix has been available since versions 15.5.24 and 16.3.3.

  • A critical vulnerability (CVE-2026-75604, CVSS 9.0) affects a broad range of Next.js versions, from 13.4.0 to 16.3.2 depending on the branch.
  • Unpatched sites are exposed to remote code execution and denial-of-service attacks.
  • Vercel released patches in rapid succession in May, September, and October 2026 — a pace that demands continuous monitoring, not occasional checks.
  • The secure versions are 15.5.24+ (15.x LTS branch) and 16.3.3+ (16.x LTS branch), or even more recent depending on the update applied.
  • A professional security audit remains the only reliable way to verify the actual exposure of a Next.js platform, beyond simply checking the version number.

Why the 2026 Next.js security vulnerability is critical for your SME

Because a CVSS score of 9.0 out of 10 means an attacker can execute code remotely without even authenticating — and because an SME typically lacks both the team and the processes to detect an intrusion before it’s too late.

Vulnerability CVE-2026-75604 is not a minor bug you fix “when you have time.” It involves unauthenticated remote code execution, specifically affecting the image optimization API when using the AVIF format, with a secondary vector on Windows-hosted servers. Two critical flaws addressed in the same update. CERT Santé rates this vulnerability at 9.0 on the CVSS v3.1 scale — in other words, it falls into the category of absolute emergencies, the kind that justifies pausing a product roadmap to patch within the day.

For an SME, the stakes go beyond the technical. A compromised e-commerce site means exposed customer data. A hacked business application means operations grinding to a halt. And unlike a large enterprise, an SME often has no SOC, no on-call rotation, and no budget to handle a security crisis urgently over the weekend.

The real cost of an unpatched flaw versus preventive maintenance

No one ever truly quantifies this trade-off, so let’s do it simply. On one hand, a Next.js security update takes a few hours of work for a properly structured application. On the other, a compromise exploiting remote code execution can lead to the loss of customer data, site downtime during remediation, a damaged reputation with your prospects, and potentially GDPR-related notification obligations if personal data is affected. The cost-benefit ratio leaves no doubt: preventive maintenance costs a fraction of what a crisis costs. This is a calculation every SME leader should make once, so they never have to revisit it.

Command-line interface displaying the Next.js version

How to check if your Next.js site is affected by this vulnerability

You need to identify the exact version of Next.js used in your project, then compare it against the published vulnerable version ranges — an operation your developer or agency can perform in a few minutes via the package.json file.

The check doesn’t require advanced skills, but it does require knowing where to look. The Next.js version is listed in the project’s dependency file (package.json), or visible via the command that lists installed packages. If you don’t manage this file yourself, ask the person or agency maintaining your site directly.

Which Next.js versions are vulnerable and how to identify them

  1. Open the package.json file of the Next.js project
  2. Locate the exact version number specified for the “next” dependency
  3. Compare this version against the known vulnerable ranges (13.4.0–15.5.23, 16.0.0–16.3.2 for CVE-2026-75604, but also the earlier ranges linked to the May and September 2026 flaws)
  4. Check if the site uses the image optimization API with AVIF files, an identified attack vector
  5. Check the hosting system: Windows servers are affected by a distinct vector
  6. Review server logs for abnormal requests on image routes or server function endpoints
  7. Commission a security audit if the project hasn’t been maintained for several months

Why a recent version doesn’t guarantee protection

A point many leaders overlook: the 16.x branch, despite being more recent, is not spared. People often assume an “up-to-date” version in absolute terms is sufficient. Wrong. What matters is the precise version relative to the patched range, not the overall recency of the framework. CVE-2026-75604 affects versions 16.0.0 to 16.3.2, with a CVSS score of 9.0.

Comparison of major Next.js vulnerabilities in 2026

The following table summarizes the three waves of patches released in 2026: three updates, three different severity levels, but one consistent message — vigilance must be continuous, not occasional.

PeriodPatched VersionsSeverity
May 202615.5.18 / 16.2.613 advisories (DoS, SSRF, XSS)
September 202615.5.27 / 16.3.8Multiple vulnerabilities
October 202615.5.24 / 16.3.32 critical, 1 high

In practical terms, if your version hasn’t been updated since spring 2026, your site has likely accumulated several unpatched flaws — not just one. It’s the stacking that makes the situation dangerous, far more than an isolated flaw.

What are the immediate actions to secure your Next.js application?

Update to version 15.5.24 or higher (15.x branch) or 16.3.3 or higher (16.x branch), test the application in a pre-production environment, then deploy — in that order, without skipping any step even under pressure.

The temptation, when facing a critical alert, is to push the update directly to production. Bad idea. Next.js evolves quickly, and a version upgrade can break components, API calls, or static rendering configurations if the project has been customized. Better to lose two hours in testing than a weekend debugging in production.

The update steps to follow in order

  • Check the current version of Next.js installed on the project
  • Identify the target version according to the branch (15.x LTS Maintenance or 16.x LTS Active)
  • Back up the code and database before any intervention
  • Apply the update in a test environment
  • Verify the rendering of critical components (props, component children, CSS classes)
  • Check server logs for any prior exploitation attempt
  • Deploy to production once tests are validated

A business owner once told me: “our site is running, why touch something that works?” That’s exactly the reasoning that leaves a door open to remote code execution for months.

The specific case of Windows hosting

Another reflex to adopt: if your hosting runs on Windows, the path traversal vector identified in CVE-2026-75604 directly concerns you. Many hosting providers in France still use Windows servers for legacy .NET applications coupled with a Next.js frontend — a scenario often overlooked in generic audits.

Gears symbolizing continuous maintenance of a Next.js system

How does regular maintenance prevent Next.js security vulnerabilities?

Because Next.js published at least three waves of security patches in 2026 (May, September, October), occasional monitoring is no longer enough — only continuous monitoring of versions and official announcements allows you to apply a patch before it’s exploited.

The pace of vulnerability disclosures for Next.js should be enough to convince any leader to abandon the idea of a site “we put online and never touch again.” Each update fixes real problems: middleware bypass, server-side request forgery, cache poisoning, cross-site scripting, excessive memory consumption leading to denial of service. These are not abstract technical details; they are the gateway to your data and your customers’ data.

Preventive maintenance, in concrete terms, is a contract that includes monitoring security announcements, rapid application of patches, and non-regression testing with each version upgrade. Without this follow-up, every update becomes an improvised emergency project rather than a controlled routine operation.

The October 2026 Next.js flaw shows a CVSS score of 9.0, compared to 6.3 for the memory consumption flaw

Vulnerability CVE-2026-75604, patched in October 2026, receives a CVSS v3.1 score of 9.0 according to CERT Santé — a critical level. By comparison, vulnerability CVE-2026-64646, related to excessive memory consumption, shows a CVSS 4.0 score of 6.3 according to NIST, a medium level. The gap illustrates why not all Next.js flaws demand the same urgency of treatment. A score of 9.0 justifies a fix within hours of the announcement, while a score of 6.3 can be handled within a planned maintenance cycle. Knowing how to distinguish between the two avoids treating every alert with the same panic — or the same negligence.

The October 2026 Next.js flaw shows a CVSS score of 9.0, compared to 6.3 for the memory consumption flaw CVE-2026-75604 9 CVSS CVE-2026-64646 6.3 CVSS
CERT Santé / NIST
ElementValue (CVSS)
CVE-2026-756049 CVSS
CVE-2026-646466.3 CVSS
Team of cybersecurity experts working on protecting a website

Why choose an expert agency for the security and maintenance of your Next.js site?

Because an agency that develops with Next.js daily knows the vulnerable versions before they make headlines and can apply a tested patch within hours — unlike internal monitoring that discovers the flaw after the fact, or even after the incident.

Serious web development doesn’t stop at launch. In fact, from a security perspective, that’s where the real work begins. A digital agency that masters Next.js, React, and Node.js continuously monitors Vercel’s official announcements, knows how to distinguish a minor flaw from a critical emergency, and has the project’s history to know precisely what a version upgrade will or won’t break.

This is the entire advantage of a well-structured offshore model: a technical team working on your Next.js project over the long term, with follow-up in a client portal, rather than an occasional provider who only returns when you call them in an emergency. At Skyward Agency, this logic translates into a single point of contact from initial scoping through to post-launch follow-up — including security patches, which are an integral part of the hosting and maintenance service, not an option discovered after the fact in a quote.

Depending on your situation

A Mauritian SME with a Next.js showcase site developed two years ago

This type of site is likely running on a version prior to 15.x or very early 15.x, never updated since delivery. What matters here: the risk is high because several waves of patches have been missed at once, not just one. The recommendation is a complete security audit before any update, to map the actual exposure before acting urgently.

A French startup with a Next.js web app in active development

Here, the team pushes code regularly, which changes the game: dependencies are likely more recent, but the pace of development makes security monitoring easy to neglect in favor of features. The priority is to integrate automated version control into the deployment cycle, so a critical alert like CVE-2026-75604 triggers immediate action, not a forgotten backlog item.

A mid-sized company with multiple Next.js applications spread across internal teams and providers

The difficulty here is not technical; it’s organizational: who is responsible for monitoring each application? Without clear centralization, a flaw patched on one project can remain open on another for months. The recommendation is support from an external team capable of supervising the entire application portfolio, with unified reporting rather than scattered maintenance silos.

Frequently asked questions about Next.js security

What are the most common Next.js security vulnerabilities?

The most common Next.js security vulnerabilities include remote code execution (like CVE-2026-75604), server-side request forgery, cross-site scripting, middleware bypass, and cache poisoning. These represent the primary Next.js vulnerabilities list that developers should monitor, as they can lead to severe Next.js data exposure risks if left unpatched.

How can I secure my Next.js application from XSS attacks?

To prevent XSS in Next.js, always sanitize user inputs, avoid dangerouslySetInnerHTML, leverage Content Security Policy headers, and keep your framework updated. These Next.js security best practices are essential for any secure Next.js application, especially when dealing with common Next.js security flaws related to client-side rendering.

Does Next.js have built-in security features?

Yes, Next.js includes built-in protections like automatic escaping in JSX, strict Content Security Policy support, and middleware for request validation. However, these features don’t eliminate Next.js SSR security concerns entirely — client-side security Next.js still requires careful implementation, particularly for API routes and data fetching.

What are the best practices for Next.js API route security?

Implement proper authentication and authorization on every API route, validate all inputs server-side, use rate limiting, and never expose sensitive environment variables to the client. These measures directly address how to prevent data leakage in a Next.js app and form the foundation of a secure Next.js application architecture.

The 2026 Next.js security vulnerability is not an isolated episode: on October 14, 2026, Next.js released an update fixing three vulnerabilities, including two critical and one high, following a May patch that already addressed 13 security advisories. Waiting for the next alert to act is taking a risk that few SMEs can truly absorb. If your Next.js site or application hasn’t been checked recently, the right reflex is to request a security audit from a team that tracks these developments daily, rather than discovering them after the fact.

See also

Skyward Agency

A web or SEO project in mind?

Website design, search visibility, custom development — get a free, no-commitment quote from our team in France and Mauritius. No templates, everything built for you.

Lucas Lamanthe LucasFounder — Skyward Agency

Your project deserves more than a quote: let’s talk.

30 minutes with Lucas to scope your project, budget and timeline — no strings attached.

Next slots available this week.

Book a discovery call