Next.js security advisory (AV26-851)
Serial Number: AV26-851 Date: August 26, 2026 As of August 25, 2026, Next.js is affected by critical vulnerabilities in the following product: Next.js Version 15.5 prior to 15.5.24 Version 16.3 prior to 16.3.3 The Cyber Centre encourages users and administrators to review the web link provided and apply any necessary updates as they become available. August 2026 Security Release
CSIRTS triage
- What
- Critical vulnerabilities in Next.js allow remote code execution or related exploitation.
- Who is affected
- Deployments running Next.js versions 15.5 before 15.5.24 and 16.3 before 16.3.3.
- Urgency
- Critical severity requires immediate remediation; exploit status unknown but critical rating indicates high risk.
- Action
- Update Next.js to version 15.5.24 or 16.3.3 or later as soon as possible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Next.js
Get an email when a new Next.js advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/nextjs-security-advisory-av26-851
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-883) – Update 12026-09-04
- unknownSUSE Linux security advisory (AV26-882)2026-09-03
- unknown[Control Systems] Siemens security advisory (AV26-881)2026-09-03
- unknownn8n security advisory (AV26-880)2026-09-03
- unknownAMD security advisory (AV26-879)2026-09-03