Cyber Resilience
← All news
Confirmed

Next.js security advisory (AV26-851)

Our takeCCC's advisory flags critical flaws in Next.js 15.5 before 15.5.24 and 16.3 before 16.3.3. Update if you self-host; hosted platforms have already applied it.
Sources (5)
What this means for you — Security leader:Update Next.js to 15.5.24 or 16.3.3+ immediately if you self-host any affected versions.
What this means for you — Lean IT orgs:Update Next.js to version 15.5.24 or 16.3.3 or newer as soon as you can.
What this means for you — MSP:Check all client Next.js deployments and update to 15.5.24+ or 16.3.3+; most affected versions are still exposed.
What this means for you — Researcher:Canadian CCCS advisory flags critical flaws in Next.js 15.5 < 15.5.24 and 16.3 < 16.3.3; update now.