Next.js is preparing a scheduled security release for September 30, 2026. This advance notice gives teams time to plan upgrades before patches are published.
The September 30 release will address nine vulnerabilities in Next.js: one critical, two high, five medium, and one low. We plan to publish 16.3.7 and 15.5.27 alongside the full advisories, including impact, affected versions, and upgrade instructions. We recommend upgrading to a patched version once the release is available.
Our security program
We work with security researchers to secure Next.js and other open source frameworks through Vercel's Open Source Bug Bounty. Anyone interested in contributing to the security of eligible frameworks is encouraged to participate there.
Any questions or concerns regarding our security programs or vulnerability management can be sent to security@vercel.com.









