The Next.js September security release is planned for September 30, 2026.
It will address nine vulnerabilities, including one critical and two high-severity issues, with fixes in 16.3.7 and 15.5.27. Upgrade once they are available.
https://t.co/eg3q4PBf4M
An out-of-band Next.js security update is planned for September 22, 2026.
It addresses a critical issue in an upstream dependency. Upgrade to Next.js 16.3.6 or 15.5.26 as soon as they are available.
https://t.co/MnezDXJIjM
We’ve moved the scheduled August Next.js security release forward to today, August 25, to include a fix for an additional critical severity vulnerability.
https://t.co/HrFZOoVcGE
Next.js 16.3.3 and 15.5.24 will include fixes for both vulnerabilities. Upgrade once they are available.
In July, we began announcing Next.js security releases ahead of time. The next security release is planned for August 26, 2026.
It will address one critical severity vulnerability with fixes in 16.3.2 and 15.5.24, so upgrade once they are available.
https://t.co/hK9GuzN8u5
⚠️ The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026.
Details: https://t.co/brFBXTT62O
🚨 Ongoing supply chain attack on Composer packages! We just found multiple laravel-lang/* packages compromised on Packagist (lang, http-statuses, attributes). Payload runs at autoload time. At least 50 package versions were compromised.
If you installed a compromised version, the malware already executed. Pin to a clean COMMIT (not version) and rotate secrets immediately.
If your lockfile already had an older commit from before today, you are safe. But you should not update at the moment.