August 27, 2026
- Next.js CVE-2026-75604 (CVSS 9.0) allows arbitrary code execution on the application server, but only for Windows-hosted apps using both Pages and App router without the Cache Component; a second patched flaw executes code via a malicious media file (NCSC-NL). · Vulnerabilities & Exploits