← Back to Resources
Open Source NewsAugust 25, 20262 min read

August 2026 Security Release: Two Critical RCEs Patched

By BIOS Founding Team

August 2026 Security Release: Two Critical RCEs Patched

Next.js confirmed the previously flagged 'advance notice' security release actually shipped, moved forward a day after a second critical vulnerability was identified. Versions 16.3.3 and 15.5.24 addressed two critical-severity, unauthenticated remote-code-execution vulnerabilities.

The first, tied to an upstream AVIF-decoding flaw, affects the Image Optimization API. The second affects Windows-hosted servers using both the Pages Router and App Router without Cache Components, with no known workaround for affected Windows deployments; Linux and macOS are unaffected. All users on 15.5.x or 16.3.x are urged to upgrade immediately.

Full details: https://nextjs.org/blog/august-2026-security-release