CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64641

highCVSS 7.5covered by 3 sourcesfirst seen 2026-07-22
An attacker can exploit multiple vulnerabilities in Vercel Next.js to manipulate data, disclose information, conduct a denial of service attack, and bypass security measures.

CSIRTS triage

What
Multiple vulnerabilities can be exploited to manipulate data, disclose information, and conduct denial of service attacks.
Who is affected
Users of Vercel Next.js.
Urgency
Remediation is urgent due to the potential for severe impacts from these vulnerabilities.
Action
Update to the latest version of Vercel Next.js.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64641

Get an email if CVE-2026-64641 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-64641

CVE.org record

Embed the live status

CVE-2026-64641 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64641 status](https://www.csirts.com/badge/CVE-2026-64641)](https://www.csirts.com/cve/CVE-2026-64641)