The Hacker News · 8/27/2026

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Two critical-severity Next.js vulnerabilities enable unauthenticated RCE: one via malicious AVIF images, one via Windows path traversal. Affects development and deployment pipeline.

Read original coverage