{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/next.js-16.0.0-to-16.3.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Next.js (13.4 to 15.5.23)","Next.js (16.0.0 to 16.3.2)","Next.js"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","rce","path-traversal","windows","nextjs"],"_cs_type":"advisory","_cs_vendors":["Vercel"],"content_html":"\u003cp\u003eCVE-2026-75604 is a critical vulnerability affecting Next.js applications hosted on Windows environments. The flaw originates in the \u003ccode\u003eFileSystemCache\u003c/code\u003e component, which fails to correctly identify backslashes (\u003ccode\u003e\\\u003c/code\u003e) as path separators on Windows systems. This improper validation enables path traversal attacks via the \u003ccode\u003e..%5C\u003c/code\u003e sequence. An unauthenticated attacker can exploit this to access the sensitive \u003ccode\u003eserver-reference-manifest.json\u003c/code\u003e file, which contains the \u003ccode\u003eencryptionKey\u003c/code\u003e used for Server Actions. Possession of this key allows an attacker to forge legitimate-looking, closure-based Server Action requests. When these forged requests are processed by the server, they lead to unauthenticated remote command execution (RCE) on the underlying host. The vulnerability specifically impacts configurations that utilize both the Pages Router and the App Router without Cache Components enabled.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Windows-hosted Next.js application using both Pages and App Routers.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing the \u003ccode\u003e..%5C\u003c/code\u003e traversal sequence.\u003c/li\u003e\n\u003cli\u003eThe request exploits the \u003ccode\u003eFileSystemCache\u003c/code\u003e path parsing flaw to bypass cache directory constraints.\u003c/li\u003e\n\u003cli\u003eThe application improperly returns the contents of the \u003ccode\u003eserver-reference-manifest.json\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to extract the \u003ccode\u003eencryptionKey\u003c/code\u003e used for signing Server Actions.\u003c/li\u003e\n\u003cli\u003eAttacker signs a malicious Server Action payload using the stolen \u003ccode\u003eencryptionKey\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker submits the forged Server Action request to the target application.\u003c/li\u003e\n\u003cli\u003eThe Next.js application executes the attacker-supplied command within the server-side runtime, resulting in full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthenticated remote command execution on the host server. Given the nature of Server Actions, attackers can gain code execution with the privileges of the service account running the Next.js application. This impacts any enterprise organization running Next.js versions between 13.4 and 15.5.23 or 16.0.0 and 16.3.2 on Windows platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch all instances of Next.js to versions \u003ccode\u003e15.5.24\u003c/code\u003e or \u003ccode\u003e16.3.3\u003c/code\u003e to remediate CVE-2026-75604.\u003c/li\u003e\n\u003cli\u003eInspect web server logs for HTTP requests containing the \u003ccode\u003e..%5C\u003c/code\u003e traversal string directed at cache-related endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for abnormal child processes spawned by the web application service account (e.g., \u003ccode\u003ecmd.exe\u003c/code\u003e, \u003ccode\u003epowershell.exe\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eReview configuration files for any instances where Pages and App Routers coexist without explicit Cache Component definitions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T14:02:44Z","date_published":"2026-08-26T13:04:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nextjs-rce/","summary":"A critical path traversal vulnerability (CVE-2026-75604) in the Next.js FileSystemCache on Windows allows unauthenticated attackers to steal Server Action encryption keys and execute arbitrary commands.","title":"Unauthenticated Remote Command Execution in Next.js on Windows","url":"https://feed.craftedsignal.io/briefs/2026-08-nextjs-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Next.js (16.0.0 to 16.3.2)","version":"https://jsonfeed.org/version/1.1"}