Next.js released v16.3.3 and v15.5.24 to remediate two critical unauthenticated remote-code-execution vulnerabilities. One flaw can be triggered when the Image Optimization API processes an attacker-controlled AVIF image through the sharp dependency and its underlying libheif library; Next.js disabled AVIF optimization while awaiting propagation of an upstream libheif fix.
The second vulnerability, CVE-2026-75604, affects Windows-hosted applications using both the Pages Router and App Router without Cache Components; Linux and macOS deployments are not affected, and no workaround is available. The Canadian Centre for Cyber Security advised organizations running Next.js 15.5 earlier than 15.5.24 or 16.3 earlier than 16.3.3 to review the security release and apply the updates.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record detailed that improperly escaped encoded Windows path separators can traverse outside Next.js incremental-cache paths on affected Windows deployments. The traversal may expose private build data, including the server-reference-manifest encryption key, whose disclosure can enable remote code execution.
The Canadian Centre for Cyber Security issued advisory AV26-851 warning that Next.js 15.5 before 15.5.24 and 16.3 before 16.3.3 are affected by critical vulnerabilities. It urged users and administrators to review the August 2026 security release and apply available updates.
Technical details identified GHSA-g89c-p67h-r497 as a libheif heap buffer overflow underlying the malicious AVIF/HEIC processing path in Next.js Image Optimization. The flaw can create duplicate Alpha planes with different bit depths, leading to an undersized allocation and 16-bit writes; libheif 1.23.2 was identified as the patched upstream version.
Next.js released versions 16.3.3 and 15.5.24 to address two critical unauthenticated remote-code-execution vulnerabilities. One involves attacker-controlled AVIF images processed by the Image Optimization API through sharp and libheif; the releases disable AVIF optimization pending an upstream libheif fix. The other, CVE-2026-75604, affects Windows-hosted applications using both Pages Router and App Router without Cache Components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecsirt.bj
Open sourcecsirt.sk
Open sourceheise.de
Open sourcenextjs.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcevercel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.