Update Next.js to the latest patched version as soon as possible. If immediate patching is not feasible, restrict access to Next.js applications and disable AVIF image processing if possible. Monitor official Vercel advisories for further details.
Quick answers
What is CVE-2026-75604?
Update Next.js to the latest patched version as soon as possible. If immediate patching is not feasible, restrict access to Next.js applications and disable AVIF image processing if possible. Monitor official Vercel advisories for further details.
How severe is CVE-2026-75604?
critical
Is CVE-2026-75604 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-75604 be mitigated?
Update Next.js to the latest patched version as soon as possible. If immediate patching is not feasible, restrict access to Next.js applications and disable AVIF image processing if possible. Monitor official Vercel advisories for further details.
CVSS
—
Vendor
Vercel
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Next.js
Mitigation
Update Next.js to the latest patched version as soon as possible. If immediate patching is not feasible, restrict access to Next.js applications and disable AVIF image processing if possible. Monitor official Vercel advisories for further details.
Vercel has patched two critical-severity vulnerabilities in Next.js that allow unauthenticated remote code execution. One flaw is a path traversal issue affecting Windows filesystems (CVE-2026-75604), and the other involves specially crafted AVIF image files. Users are urged to update immediately.