🚨 ALERT — CRITICAL NEXT.JS RCE
DATE: September 22, 2026
CONFIRMED BY: Next.js / Vercel
PRODUCT: Next.js next/og ImageResponse
CVE: CVE-2026-94545
SEVERITY: Critical — CVSS 9.5
IMPACT:
Attacker-controlled values rendered through the Node.js ImageResponse implementation can, under affected conditions, lead to Remote Code Execution on the server.
AFFECTED VERSIONS:
Next.js >=16.2.0 and <16.3.6
FIXED VERSION:
Next.js 16.3.6
EXPLOITATION STATUS:
RCE impact confirmed by the vendor.
No confirmed in-the-wild exploitation found at this time.
URGENT ACTION:
Upgrade to Next.js 16.3.6 immediately.
Until patched, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by Node.js ImageResponse.
SOURCE:
https://nextjs.org/blog/nextjs-security-update-september-22-2026
TECHNICAL ADVISORY:
https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j
#CyberSecurity #InfoSec #ThreatIntel #NextJS #Vercel #CVE #CVE202694545 #RCE #WebSecurity #Vulnerability #SecOps