Next.js July 2026 Security Patch: Fix SSRF, Middleware Bypass, and DoS Now
Next.js patched 9 CVEs on July 21 — 4 rated HIGH. A Turbopack middleware bypass (CVE-2026-64642) silently skips auth checks. Upgrade to 15.5.21 ...
Privacy, vulnerabilities, authentication, and cybersecurity