Critical Unauthenticated RCE in Next.js via AVIF Image (CVE‑2026‑XXXX) and Windows Path Traversal (CVE‑2026‑75604)
What It Is – Vercel disclosed two critical‑severity flaws in the popular Next.js framework. One flaw can be triggered by a malicious AVIF image, leading to unauthenticated remote code execution (RCE). The second is a Windows‑specific path‑traversal (CVE‑2026‑75604) that also enables unauthenticated RCE on servers using a Windows filesystem.
Exploitability – Both vulnerabilities are actively exploitable; proof‑of‑concept exploits have been published. CVSS scores are 9.8 (critical) for each.
Affected Products – Next.js (all supported versions prior to the August 2026 patches). The Windows path‑traversal only impacts deployments on Windows hosts.
Why It Matters for Compliance & Audit Readiness
- Control Mapping – Demonstrating that you have a documented, continuously‑monitored process for tracking and remediating critical vulnerabilities satisfies SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management).
- Audit Evidence – Automated collection of patch‑status evidence (e.g., CI/CD pipeline logs, vulnerability scanner reports) provides defensible proof during SOC 2 examinations and third‑party risk assessments.
- Enterprise Buyer Expectations – Modern SaaS buyers increasingly require proof that critical RCE bugs are patched within defined SLAs; a robust control‑mapping program meets that demand.
Recommended Actions
- Upgrade all Next.js instances to the patched version released on 2026‑08‑01.
- Verify that no legacy AVIF processing libraries remain in production.
- Integrate vulnerability‑remediation status into your CI/CD pipeline and map the fix to SOC 2 CC6.1 controls.
- Capture and retain patch‑deployment logs as continuous audit evidence.
Source: The Hacker News – Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE