CRITICAL 9 CVE-2026-75604 Published 1 Sept 2026

Next.js Windows Path Traversal Vulnerability

Worried this affects one of your servers?

Next.js, a React framework for building full-stack web applications, is affected by a vulnerability in versions 13.4.0 to 15.5.24 and 16.3.3.

Due to inconsistent backslash escaping in route segments, remote requests can exploit Windows path separators to traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key.

This can lead to remote code execution in the affected application. The issue is fixed in versions 15.5.24 and 16.3.3.

Reference: CVE-2026-75604 on NVD

← Back to Security News