CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Next.js security advisory (AV26-851)

critical
Serial Number: AV26-851 Date: August 26, 2026 As of August 25, 2026, Next.js is affected by critical vulnerabilities in the following product: Next.js Version 15.5 prior to 15.5.24 Version 16.3 prior to 16.3.3 The Cyber Centre encourages users and administrators to review the web link provided and apply any necessary updates as they become available. August 2026 Security Release

CSIRTS triage

vendor: Vercelproduct: Next.jsRemote code executionaffected: 15.5 prior to 15.5.24, 16.3 prior to 16.3.3
What
Critical vulnerabilities in Next.js allow remote code execution or related exploitation.
Who is affected
Deployments running Next.js versions 15.5 before 15.5.24 and 16.3 before 16.3.3.
Urgency
Critical severity requires immediate remediation; exploit status unknown but critical rating indicates high risk.
Action
Update Next.js to version 15.5.24 or 16.3.3 or later as soon as possible.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Next.js

Get an email when a new Next.js advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-08-26
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/nextjs-security-advisory-av26-851

More from Canadian Centre for Cyber Security