If your business website or web application runs on Next.js, this is the right time to review its security posture. Recent Next.js security updates show why keeping frameworks and dependencies current is not optional; it is a core part of protecting your users, application data, and business operations.
On 22 September 2026, the Next.js team released an urgent security update after identifying a critical issue in an upstream dependency. A second scheduled release is also planned for 30 September, covering nine more vulnerabilities across different severity levels. For teams using React and Next.js, the message is simple: check your deployed version, apply the correct security patch, and make dependency monitoring part of your regular development workflow.
What Went Wrong? Recent Next.js Vulnerabilities
The most urgent Next.js security vulnerability announced this month affects the Node.js implementation of Image Response in next/og. This feature is commonly used to generate dynamic Open Graph images; for example, the preview image displayed when someone shares a blog post or product page on LinkedIn, X, or WhatsApp.
The issue involved improper escaping in SVG output generated through an upstream dependency called Satori. Under specific conditions, the vulnerability could potentially lead to remote code execution (RCE). In simple terms, remote code execution is a serious risk because it may allow an attacker to execute unwanted code on a vulnerable server.
The affected Next.js range is:
Text |
Next.js >= 16.2.0 and < 16.3.6 |
This issue affects the Node.js ImageResponse implementation. Applications using the Edge implementation of ImageResponse are not affected by this particular vulnerability. Next.js 15.x is also not affected by this RCE issue, although the latest 15.5 patch includes related security hardening.
Why This Matters for Businesses
A framework vulnerability does not automatically mean every website has been compromised. However, it does mean teams should quickly identify whether their application:
Uses an affected Next.js version.
Uses next/og or ImageResponse on the Node.js runtime.
Processes untrusted or user-controlled input in image-generation logic.
Has outdated packages or incomplete dependency monitoring.
Security incidents are often not caused by one mistake. They usually happen when an unpatched framework, unreviewed third-party package, exposed server setting, or weak deployment process creates an opportunity for attackers.
The September 2026 Next.js Security Patches
The first important Next.js security update was released on 22 September 2026. Next.js published the following versions:
Release Branch | Recommended Patch Version | Purpose |
Next.js 16.3 | 16.3.6 | Fixed next/org & Imageresponse |
Next.js 15.5 | 15.5.26 | Related Security Issues |
For applications using an affected 16.2 or 16.3 version, the recommended upgrade command is:
Bash |
npm install next@16.3.6 |
For teams maintaining the 15.5 branch:
Bash |
npm install next@15.5.26 |
These patches update upstream dependencies, including Satori, to address the identified risk.
Another Update Is Coming
Next.js has also announced a scheduled security release for 30 September 2026. According to the announcement, the release will address nine vulnerabilities:
One critical vulnerability.
Two high-severity vulnerabilities.
Five medium-severity vulnerabilities.
One low-severity vulnerability.
The planned releases are 16.3.7 and 15.5.27. Full advisories, affected-version details, and exact upgrade guidance are expected alongside the release. Teams should plan a maintenance window now and update as soon as the patches become available.
How to Respond: A Practical Security Checklist
A quick update is important, but a safe update process is even better. Use this Next.js security checklist to respond responsibly.
1. Check Your Current Next.js Version
Run this command from your project directory:
Bash |
npm list next |
You can also check the dependencies section in your package.json file. If you are on Next.js 16.2.0 through 16.3.5, treat the update as urgent.
2. Upgrade to the Correct Version
Use the official patched version for your release branch. Avoid upgrading blindly to an unfamiliar major release during an emergency patch unless your testing process supports it.
After upgrading, commit both packages. Commit the package JSON file and your lock file, such as package-lock.json, yarn.lock, or pnpm-lock.yaml. This helps ensure your development, staging, and production environments use the same secure dependency versions.
3. Test Before Production Deployment
Run your normal quality checks after the update:
Bash |
npm run lint |
npm run test |
npm run build |
Then deploy to a staging environment and test critical journeys such as login, payments, forms, APIs, content pages, and image-generation routes. If your application uses next/og, test each route that creates social-sharing or Open Graph images.
4. Review Server Logs and Alerts
After deployment, review error logs, server activity, and application monitoring alerts. Look for unexpected failures, unusual API activity, repeated errors on image-generation endpoints, or unauthorized changes.
5. Schedule the 30 September Upgrade
Do not wait until the day of release to decide who will handle the update. Assign an owner, create a maintenance ticket, prepare a rollback plan, and monitor the official Next.js security advisory when the patches are published.
Beyond Next.js: Keep Dependencies Healthy
A strong Next.js security strategy goes beyond the framework itself. Modern applications depend on many npm packages, and even trusted packages can introduce risk when versions become outdated.
Use these tools in your workflow:
npm audit to identify known dependency vulnerabilities.
Dependabot or Renovate to create automated dependency update pull requests.
GitHub Security Advisories to monitor disclosed issues.
Snyk, Socket, or similar tools to scan packages and software supply-chain risks.
A software bill of materials (SBOM) for larger projects that need better visibility into production dependencies.
For example, the next/link npm package is not installed separately in normal Next.js projects; it is part of the next package. Likewise, many developers search for terms such as next server npm or next react version, but the safest approach is to review your full dependency tree rather than updating isolated packages without context.
Proactive Security in DevOps
The best Next.js security best practices are proactive, repeatable, and built into your delivery process. Security should not depend on a developer remembering to check the news every week.
At QTO Dev, we recommend building these controls into CI/CD:
Run dependency-vulnerability scans on every pull request.
Block deployments when critical vulnerabilities are detected.
Keep staging and production environments separate.
Store secrets in a secure secrets manager, not in source code.
Apply secure HTTP headers, including Content Security Policy, HSTS, X-Content-Type-Options, and Referrer-Policy.
Enable monitoring, error tracking, and alerting for production applications.
Review dependencies regularly; not only after a public security incident.
A secure web application is not created by one plugin or one patch. It comes from continuous updates, controlled deployments, visibility into risks, and an experienced team that treats security as part of software quality.
QTO Dev Security Alert Column
Action required: If your app uses Next.js >=16.2.0 and <16.3.6, upgrade to next@16.3.6 immediately, especially if you use Node.js ImageResponse through next/og. Also prepare to review and apply the scheduled 30 September update when Next.js releases 16.3.7 and 15.5.27.



