Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel releases urgent security updates for two critical vulnerabilities in the Next.js framework, including a path traversal on Windows and an AVIF image parsing flaw.

Key Takeaways
- Two critical vulnerabilities in Next.js allow unauthenticated remote code execution.
- CVE-2026-75604 is a path traversal flaw affecting Windows filesystems.
- A second flaw is triggered by specially crafted AVIF image files.
- Vercel has released patches; users should update immediately.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


