Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
- Posted on August 27, 2026
- By The Hacker News
- 1 Views
- 1 min read
Next.js has released urgent security updates addressing two severe vulnerabilities that could allow attackers to execute arbitrary code without authentication. These flaws specifically impact Windows-based deployments and applications utilizing AVIF image optimization features. Organizations running affected versions should prioritize immediate patching to prevent potential system compromise and unauthorized access to their infrastructure.
Summary auto-generated by AI from the original publisher's content. Editorial standards.