Next.js security advisory (AV26-851)
Canada's Cyber Centre warns Next.js 15.5 and 16.3 are affected by critical vulnerabilities; users should update to 15.5.24 and 16.3.3.
The Canadian Centre for Cyber Security (AV26-851) warns that Next.js versions 15.5 prior to 15.5.24 and 16.3 prior to 16.3.3 are affected by critical vulnerabilities. Administrators are urged to review the vendor advisory and apply the August 2026 security release updates. The bulletin provides no CVE ids or exploitation details.
65