CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-75604: Next.js Windows Path Traversal Enables Unauthenticated RCE

August 27, 2026

A critical path traversal vulnerability in Next.js (CVSS 9.0) affects applications using Pages Router or App Router without Cache Components on Windows filesystems. It allows unauthenticated remote code execution. Patches are available in Next.js 15.5.24 and 16.3.3.