ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

Next.js security advisory (AV26-851)

highAdvisoryimportance 65
AI summary · glm-5.3-flash

Canada's Cyber Centre warns Next.js 15.5 and 16.3 are affected by critical vulnerabilities; users should update to 15.5.24 and 16.3.3.

The Canadian Centre for Cyber Security (AV26-851) warns that Next.js versions 15.5 prior to 15.5.24 and 16.3 prior to 16.3.3 are affected by critical vulnerabilities. Administrators are urged to review the vendor advisory and apply the August 2026 security release updates. The bulletin provides no CVE ids or exploitation details.

  • Critical vulnerabilities affect Next.js 15.5.x before 15.5.24 and 16.3.x before 16.3.3
  • Fixes ship in Next.js 15.5.24 and 16.3.3 via the August 2026 security release
  • Canadian Cyber Centre urges administrators to update promptly
Full article

Serial Number: AV26-851 Date: August 26, 2026 As of August 25, 2026, Next.js is affected by critical vulnerabilities in the following product: Next.js Version 15.5 prior to 15.5.24 Version 16.3 prior to 16.3.3 The Cyber Centre encourages users and administrators to review the web link provided and apply any necessary updates as they become available. August 2026 Security Release

This source does not provide full text. Read it at cyber.gc.ca.