Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks

Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked as CVE-2026-75604, affects Next.js applications that use either the Pages Router or the App Router without Cache Components. An attacker may exploit the issue when the affected application runs on […]

This article has been indexed from Cyber Security News

Read the original article: