HackerFeeds

CyberSecurity News

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News
· August 27, 2026

AI summary

Vercel has released patches for two critical vulnerabilities in the Next.js web framework that allow unauthenticated remote code execution. One vulnerability can be exploited through specially crafted AVIF image files, while the other is a path traversal flaw affecting Windows filesystems. The Windows path traversal issue has been assigned a CVE identifier. These vulnerabilities enable remote code execution without authentication. The patches address these critical-severity flaws in Next.js.

Read the full article at The Hacker Newsthehackernews.com/2026/08/nextjs-patches-critical-avif-and.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.