45M Weekly Downloads at Risk: Next.js CVE-2026-75604 (CVSS 9.0) Enables Unauthenticated Remote Code Execution

Author: Do Son (SecurityOnline.info) Published: August 26, 2026 Source: https://securityonline.info/nextjs-rce-vulnerability/ Summary Vercel has patched two critical, unauthenticated remote code execution flaws in Next.js, the widely used full-stack JavaScript framework. The primary bug, CVE-2026-75604 (CVSS 9.0), is a Windows-only path traversal that can lead to RCE; a second flaw in the image-optimization path (CVSS 9.5) allows … Read more