<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/august-2026-security-release-w2p4igm5c" -->

---
title: August 2026 Security Release | daily.dev
description: Next.js released v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS) to patch two critical unauthenticated remote code execution vulnerabilities. One flaw is...
canonical: https://daily.dev/posts/august-2026-security-release-w2p4igm5c
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: August 2026 Security Release | daily.dev
og:description: Next.js released v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS) to patch two critical unauthenticated remote code execution vulnerabilities. One flaw is...
og:url: https://daily.dev/posts/august-2026-security-release-w2p4igm5c
og:image: https://api.daily.dev/og/posts/W2p4IgM5c.png
og:image:alt: August 2026 Security Release
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# August 2026 Security Release

**[Next.js](https://daily.dev/sources/next)** · 2 min read · 2 upvotes · 2 comments

## Summary

Next.js released v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS) to patch two critical unauthenticated remote code execution vulnerabilities. One flaw is in the Image Optimization API when handling AVIF images due to an underlying libheif issue used by sharp, patched by disabling AVIF optimization until an upstream fix arrives. The second affects Windows-hosted servers running both Pages Router and App Router without Cache Components, with no known workaround for those setups. Linux and macOS are unaffected by the second issue. Developers are urged to update immediately via npm install next@15.5.24 or next@16.3.3.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://nextjs.org/blog/august-2026-security-release>

## Questions this post answers

### Why did Next.js move its August security release forward and what should I upgrade to?

Next.js moved its planned security release forward after finding an additional critical severity vulnerability in an upstream dependency. Patches are available in v16.3.3 for the Active LTS line and v15.5.24 for the Maintenance LTS line, addressed via npm install next@16.3.3 or npm install next@15.5.24 depending on which major version you run.

_Track Next.js security patches like this one on daily.dev before they hit production._

### What is the unauthenticated RCE vulnerability in Next.js image optimization with AVIF images?

A flaw in the libheif library used by sharp allows unauthenticated remote code execution when Next.js optimizes an attacker-controlled AVIF image, tracked as GHSA-2xp9-vwfh-vxw4 and GHSA-g89c-p67h-r497. The fix in v16.3.3 and v15.5.24 disables AVIF optimization entirely until an upstream fix in libheif is propagated.

_Developers patching image pipelines can follow Next.js security advisories like this on daily.dev._

### Are Linux and macOS servers affected by the Next.js Windows RCE vulnerability CVE-2026-75604?

No, only Windows-hosted Next.js servers are affected. The vulnerability, tracked as CVE-2026-75604 and GHSA-p293-qw3h-jr36, impacts applications using both Pages Router and App Router without Cache Components, and there is no known workaround besides upgrading to v16.3.3 or v15.5.24.

_Teams running Next.js on Windows can watch for platform-specific advisories like this via daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@petecapecod** · 0 upvotes

> And, yet AGAIN it's time for another Next upgrade. Man I gotta just put these on an agent weekly upgrade schedule 👌🏻

**@agustinbarrientos** · 0 upvotes

> Security releases should bypass the weekly upgrade cadence. First inventory Windows hosts, mixed Pages/App Router deployments, and AVIF optimization to find exposed services. After upgrading, test both affected paths instead of treating the version bump as proof.

## Similar posts on daily.dev

- [Next.js May 2026 security release](https://daily.dev/posts/next-js-may-2026-security-release-hmqrmcava) · Vercel · 130 upvotes · 4 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nextjs](https://daily.dev/tags/nextjs), [#vercel](https://daily.dev/tags/vercel)

[View this post on daily.dev](https://daily.dev/posts/august-2026-security-release-w2p4igm5c)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"August 2026 Security Release","url":"https://daily.dev/posts/august-2026-security-release-w2p4igm5c","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/august-2026-security-release-w2p4igm5c"},"datePublished":"2026-08-25T16:51:58.556Z","dateModified":"2026-08-27T14:30:38.482Z","description":"Next.js released v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS) to patch two critical unauthenticated remote code execution vulnerabilities. One flaw is...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d8341b9d8da3231afd5caa80af93821?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d8341b9d8da3231afd5caa80af93821?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Next.js","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Next.js","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/a7460ee33d92486cb5afd0fca36a116d","url":"https://daily.dev/sources/next"},"commentCount":2,"discussionUrl":"https://daily.dev/posts/august-2026-security-release-w2p4igm5c","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":2}],"keywords":"security,nextjs,vercel","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Next.js","item":"https://daily.dev/sources/next"},{"@type":"ListItem","position":3,"name":"August 2026 Security Release"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/august-2026-security-release-w2p4igm5c","comment":[{"@type":"Comment","text":"And, yet AGAIN it’s time for another Next upgrade. Man I gotta just put these on an agent weekly upgrade schedule 👌🏻","datePublished":"2026-08-26T12:30:27.304Z","url":"https://daily.dev/posts/W2p4IgM5c#c-kXIIEICR1","author":{"@type":"Person","name":"Peter Cruckshank","url":"https://daily.dev/petecapecod","image":"https://media.daily.dev/image/upload/s--ZJhQyKws--/f_auto/v1721235024/avatars/avatar_A9xh33q0QoxtkGoJRCosp"}},{"@type":"Comment","text":"Security releases should bypass the weekly upgrade cadence. First inventory Windows hosts, mixed Pages/App Router deployments, and AVIF optimization to find exposed services. After upgrading, test both affected paths instead of treating the version bump as proof.","datePublished":"2026-08-26T23:07:27.149Z","url":"https://daily.dev/posts/W2p4IgM5c#c-yW1QhJbgU","author":{"@type":"Person","name":"Agustin Barrientos","url":"https://daily.dev/agustinbarrientos","image":"https://media.daily.dev/image/upload/s--5ayxQnqn--/f_auto/v1788281802/avatars/avatar_wQYYVe5Tbj0NJ7C7qPoa8?_a=BAMAMicg0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/august-2026-security-release-w2p4igm5c#faq","mainEntity":[{"@type":"Question","name":"Why did Next.js move its August security release forward and what should I upgrade to?","acceptedAnswer":{"@type":"Answer","text":"Next.js moved its planned security release forward after finding an additional critical severity vulnerability in an upstream dependency. Patches are available in v16.3.3 for the Active LTS line and v15.5.24 for the Maintenance LTS line, addressed via npm install next@16.3.3 or npm install next@15.5.24 depending on which major version you run. Track Next.js security patches like this one on daily.dev before they hit production."}},{"@type":"Question","name":"What is the unauthenticated RCE vulnerability in Next.js image optimization with AVIF images?","acceptedAnswer":{"@type":"Answer","text":"A flaw in the libheif library used by sharp allows unauthenticated remote code execution when Next.js optimizes an attacker-controlled AVIF image, tracked as GHSA-2xp9-vwfh-vxw4 and GHSA-g89c-p67h-r497. The fix in v16.3.3 and v15.5.24 disables AVIF optimization entirely until an upstream fix in libheif is propagated. Developers patching image pipelines can follow Next.js security advisories like this on daily.dev."}},{"@type":"Question","name":"Are Linux and macOS servers affected by the Next.js Windows RCE vulnerability CVE-2026-75604?","acceptedAnswer":{"@type":"Answer","text":"No, only Windows-hosted Next.js servers are affected. The vulnerability, tracked as CVE-2026-75604 and GHSA-p293-qw3h-jr36, impacts applications using both Pages Router and App Router without Cache Components, and there is no known workaround besides upgrading to v16.3.3 or v15.5.24. Teams running Next.js on Windows can watch for platform-specific advisories like this via daily.dev."}}]}
```

