Cyber Resilience
← All news
Corroborated

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Our takeVercel patches two critical Next.js flaws allowing unauthenticated RCE — one via crafted AVIF images (CVE pending detail), one a Windows path traversal (CVE-2026-75604). Update if you self-host; Vercel-hosted apps are already covered. Windows-filesystem servers are the priority.
Sources (3)