CVE-2026-75604

Updated on 01 Sep 2026

Severity

9.0 Critical severity

Details

CVSS score
9.0
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Overview

About vulnerability

Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

Details

Affected product:
Next.js , mui-material-nextjs , pigment-css
Affected packages:
@next/env @ 16.0.6 (+63 more)

Fixes