Updated 27 Aug 2026: The scheduled release moved forward to Aug 25 and disclosed two unauthenticated critical RCEs. Adds fixed versions 16.3.3/15.5.24, the AVIF Image Optimizer/libheif path, the Windows-hosted Pages/App Router path, and the no-workaround upgrade guidance.

Key details

  1. Next.js released the August security update on August 25, 2026, one day earlier than originally scheduled.
  2. The patched versions are Next.js 16.3.3 and 15.5.24.
  3. Two vulnerabilities are rated Critical and can lead to unauthenticated remote code execution.
  4. The AVIF Image Optimization issue affects Next.js >=10.0.0 <15.5.24 and versions <16.3.3, through libheif used by sharp.
  5. The Windows-hosted RCE affects Next.js >=13.4 <15.5.24 and >=16.0 <16.3.3 when using Pages or App Router without Cache Components on a Windows filesystem.
  6. The Windows advisory says there is no known workaround besides upgrading.
  7. The original August 20 pre-announcement had said one critical vulnerability would be patched on August 26.

What builders should take away

  1. Upgrade supported production applications to Next.js 16.3.3 or 15.5.24 now rather than relying on exposure assumptions as a substitute for patching.
  2. If you self-host on Windows, prioritize the update immediately because the Windows-hosted RCE has no known workaround for affected configurations.
  3. Audit whether your Image Optimization path accepts or processes AVIF inputs, but treat that analysis as triage rather than a reason to defer the fixed release.
  4. Run regression tests around image handling, routing, server execution and deployment after upgrading, especially if the application has custom image loaders or unusual Windows hosting arrangements.
  5. Identify applications on older unsupported branches and plan a supported-line migration; a security process that cannot consume current patches is itself an operational risk.

What changed

On August 25, 2026, Next.js moved its scheduled August security release forward by one day and published Next.js 16.3.3 and 15.5.24. The release fixes two critical unauthenticated remote-code-execution vulnerabilities. One affects the Image Optimization API when AVIF files are optimized through the underlying libheif path used by sharp. The other affects Windows-hosted applications using the Pages Router or App Router without Cache Components. The pre-announcement had only identified one undisclosed critical issue and an August 26 release date; builders now have the exact affected versions, patch versions and exposure conditions.

Why it matters

This is now an actionable patch event rather than an advance warning. Both vulnerabilities are network-reachable and require no authentication, and the Windows-hosted issue has no known workaround besides upgrading. The AVIF issue affects a much broader historical version range, while the Windows issue depends on deployment environment and framework configuration. Teams should upgrade first and use the disclosed conditions to prioritize validation rather than waiting for exploit evidence.

The release moved forward and expanded to two critical flaws

Next.js published the release on August 25 rather than the originally scheduled August 26 date. The final advisory contains two critical vulnerabilities, not one. Patched releases are 16.3.3 on the Active LTS line and 15.5.24 on the Maintenance LTS line.

AVIF image optimization can lead to remote code execution

The AVIF vulnerability affects Next.js versions from 10.0.0 up to, but not including, 15.5.24 and versions before 16.3.3. Next.js says the issue originates in the libheif library used through sharp by the Image Optimization API. A malicious AVIF that reaches the optimization path can lead to remote code execution. Until the fix propagated, AVIF optimization was disabled; upgrading is the durable remediation.

Windows-hosted applications have a separate RCE path

A second vulnerability affects Next.js 13.4 through 15.5.23 and 16.0 through 16.3.2 when applications are hosted on a Windows filesystem and use the Pages Router or App Router without Cache Components. The advisory says there is no known workaround for affected Windows-hosted applications and recommends upgrading immediately.

Exposure is configuration-dependent, but patching is still the primary action

The two flaws have different prerequisites, so not every Next.js deployment is equally exposed. Linux-hosted applications are not described as affected by the Windows-specific flaw, and the AVIF issue depends on AVIF files reaching image optimization. Those distinctions are useful for incident triage, but they do not remove the need to move supported applications to 16.3.3 or 15.5.24.

What to watch next

  • Whether public proof-of-concept exploits or active exploitation emerge for either vulnerability.
  • Any further clarification from Next.js on hosting-platform exposure, mitigations or affected configurations.
  • Downstream updates from hosting providers and security vendors that automatically mitigate or detect these paths.
  • Whether the underlying libheif/sharp issue requires additional direct dependency updates outside Next.js applications.

Still unclear

  • The public advisories establish the affected version ranges and conditions, but real-world exploitability can still vary with application routing, image configuration and hosting environment.
  • No public evidence of widespread exploitation was identified during this review.

Sources

Direct reading behind this dossier.

3 sources
August 2026 Security Release
Next.js / Vercel primary

Official final release notice for 16.3.3 and 15.5.24, confirming two Critical vulnerabilities and the moved-forward release.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment