Security Update: Two critical Next.js vulnerabilities
UpdateUnverifiedAdded Sep 24, 2026
The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution. Both are patched in 15.5.24 and 16.3.3. Netlify-hosted sites are not affected by the Windows issue, and do not run the Next.js code path affected by the image issue. We still recommend upgrading.
Topics: Security
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Aug 27 | GitHub stacked pull requests now create Deploy Previewsunverified Preview | Preview |
| Aug 19 | Agent Runners can now ask clarifying questionsunverified Update | Update |
| Aug 19 | Pre-launch toolbar and the Powered by Netlify badgeunverified Update | Update |
| Sep 1 | Claude Fable 5.1 now available in AI Gateway and Agent Runnersunverified Update | Update |
| Sep 2 | Google Gemini 3.8 Flash now available in AI Gateway and Agent Runnersunverified Update | Update |
| Sep 4 | Agent Runners now use smarter scoping for new projectsunverified Preview | Preview |
| Sep 4 | GPT-6 Astra now available in AI Gateway and Agent Runnersunverified Update | Update |
| Aug 13 | Google Gemini 3.7 Flash now available in AI Gateway and Agent Runnersunverified Update | Update |
Also shipped on Aug 25, 2026
Netlify in August 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.