Vercel security patch release for CVE-2026-75604
Security Patch Release
Summary
Hide ▲
Show ▼
Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixes landed in Next.js 15.5.24 and 16.3.3, covering both a Windows path traversal issue and a flaw reachable through crafted AVIF image files. The Windows bug is tracked as CVE-2026-75604 and affects Next.js 13.4 through 15.5.23 plus 16.0 through 16.3.2. Vercel-hosted apps are reported protected, while affected Windows-hosted users were told to upgrade immediately.
Related Happenings
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
WordPress security patch release for CVE-2026-64638
Security Patch Release
H score34
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
WordPress security patch release for CVE-2026-64638
Security Patch ReleaseAbout this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
Timeline
-
27.08.2026 18:13 1 articles · 4h ago
Vercel advances its August Next.js security release
Initial DisclosureVercel moved its August patch window forward by one day after identifying an additional critical-severity vulnerability in an upstream dependency, and the company said the release now covered two critical Next.js flaws that can lead to unauthenticated remote code execution, including CVE-2026-75604 on Windows-hosted applications.
Show sources
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — thehackernews.com — 27.08.2026 18:13
-
27.08.2026 18:13 2 articles · 4h ago
Vercel publishes Next.js 15.5.24 and 16.3.3
Mitigation Patch UpdateVercel released Next.js 15.5.24 and 16.3.3 on August 25, 2026 to fix the AVIF-image remote code execution flaw and the Windows path traversal bug, told affected Windows-hosted operators to upgrade immediately, and said Vercel-hosted applications are protected without requiring an upgrade.
Show sources
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — thehackernews.com — 27.08.2026 18:13
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — thehackernews.com — 27.08.2026 18:13
-
27.08.2026 18:13 1 articles · 4h ago
AVIF optimization flaw in Next.js remains gated on libheif remediation
Technical Analysis UpdateThe AVIF issue in Next.js depends on image/avif being enabled in next.config.js and flows through sharp and libheif, where researchers said they were able to get RCE on multiple applications; by August 27, 2026, no exploitation of either August vulnerability had been reported, and the patched Next.js releases disabled AVIF optimization until an upstream libheif fix is available.
Show sources
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — thehackernews.com — 27.08.2026 18:13