Vercel security advisory (AV26-754)
Serial Number: AV26-754 Date: July 28, 2026 As of July 27, 2026, Vercel is affected by vulnerabilities in the following product: next.js Prior to 15.5.21 Prior to 16.2.11 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v15.5.21 Release v16.2.11
CSIRTS triage
- What
- Vulnerabilities have been identified in the next.js framework.
- Who is affected
- Users and administrators of next.js versions prior to the specified versions.
- Urgency
- Remediation is recommended but not urgent as the vulnerabilities are not actively exploited.
- Action
- Users should update to the latest versions 15.5.21 or 16.2.11.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch next.js
Get an email when a new next.js advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/vercel-security-advisory-av26-754
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30