Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Unauthenticated RCE in Next.js via AVIF Image (CVE‑2026‑XXXX) and Windows Path Traversal (CVE‑2026‑75604)

Vercel patched two critical Next.js flaws that allow unauthenticated remote code execution—one via crafted AVIF images, the other via a Windows path‑traversal (CVE‑2026‑75604). Organizations must map remediation to SOC 2 controls to retain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Critical Unauthenticated RCE in Next.js via AVIF Image (CVE‑2026‑XXXX) and Windows Path Traversal (CVE‑2026‑75604)

What It Is – Vercel disclosed two critical‑severity flaws in the popular Next.js framework. One flaw can be triggered by a malicious AVIF image, leading to unauthenticated remote code execution (RCE). The second is a Windows‑specific path‑traversal (CVE‑2026‑75604) that also enables unauthenticated RCE on servers using a Windows filesystem.

Exploitability – Both vulnerabilities are actively exploitable; proof‑of‑concept exploits have been published. CVSS scores are 9.8 (critical) for each.

Affected Products – Next.js (all supported versions prior to the August 2026 patches). The Windows path‑traversal only impacts deployments on Windows hosts.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – Demonstrating that you have a documented, continuously‑monitored process for tracking and remediating critical vulnerabilities satisfies SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management).
  • Audit Evidence – Automated collection of patch‑status evidence (e.g., CI/CD pipeline logs, vulnerability scanner reports) provides defensible proof during SOC 2 examinations and third‑party risk assessments.
  • Enterprise Buyer Expectations – Modern SaaS buyers increasingly require proof that critical RCE bugs are patched within defined SLAs; a robust control‑mapping program meets that demand.

Recommended Actions

  • Upgrade all Next.js instances to the patched version released on 2026‑08‑01.
  • Verify that no legacy AVIF processing libraries remain in production.
  • Integrate vulnerability‑remediation status into your CI/CD pipeline and map the fix to SOC 2 CC6.1 controls.
  • Capture and retain patch‑deployment logs as continuous audit evidence.

Source: The Hacker News – Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

📰 Original Source
https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →