September 2026 Security Release: The September 2026 security release
The September 2026 security release for Next.js is now available. September 2026 Security Release: The September 2026 security release
By Dillip Chowdary โข Oct 02, 2026 โข Source: Next.js Blog
What shipped in September 2026 Security
Next.js released its September 2026 security update to address vulnerabilities and improve the overall security posture of the web development framework. This release targets core routing mechanisms, rendering pipelines, and data fetching protocols to prevent unauthorized access and potential data leaks. By deploying these critical patches, Next.js aims to reinforce the security baseline for all production applications running on its framework. The update represents a coordinated effort by the development team to
Back to BlogWednesday, September 30th 2026SecuritySeptember 2026 Security ReleasePosted byJosh Story@joshcstoryKarim Rahal@karimpwnzSebastian Silbermann@sebsilbermannLast week we announced an upcoming security release for Next.js. A fix for one critical vulnerability and one high severity vulnerability was postponed due to upstream dependency delays.
What improved in September 2026 Security

Updates are now available in v16.3.8 (Active LTS) and v15.5.27 (Maintenance LTS) to address these issues. Please patch your Next.js dependencies to maintain the security of your applications.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What you gain from September 2026 Security
If no images.remotePatterns are configured, your application is not affected. See the full write-up from Next.js Blog via the source link for quotes and complete context.
How to get September 2026 Security
An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). Sites are affected if they enable Cache Components (or experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.
What to watch after September 2026 Security
Our security program We work with a talented set of researchers to secure Next.js and other open source frameworks through Vercel's Open Source Bug Bounty. Anyone interested in contributing to the security of eligible frameworks is encouraged to participate there.
Developer Action Items
- โ Diff the official changelog for Framework 16.3.8 before you bump โ APIs, defaults, and removed flags only.
- โ Install through the vendor's documented channel in staging; keep a one-command rollback and time-box the canary.
- โ Grep your repo for old flag names, lockfile pins, and plugin versions that the notes mark as breaking.
- โ Prefer the first patch cut over the day-zero tag unless you have a reason to be on the leading edge.
- โ If Next.js Blog did not name a region, plan, or SKU, screenshot the official availability line before you promise it to users.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement