The Next.js team at Vercel said on October 8, 2026 that it plans to ship a security update next Wednesday, October 14. It is an out-of-band release, meaning it falls outside the normal schedule. The update will fix three flaws in upstream dependencies, which are the outside software packages Next.js relies on. Vercel rates two of them Critical and one High. It also said two of the fixes were held back from the September security release because of coordination with the upstream projects.
Vercel has not yet said which dependencies are affected. It has not named the flaws or described what an attacker could do. Affected versions and upgrade steps are also still unpublished. Vercel said full advisories covering impact, affected versions and upgrade instructions will come out with the update on October 14. The post does not say whether anyone is exploiting these flaws. It tells users to move to a patched version as soon as it is available.
Teams that run or buy products built on Next.js now know a patch is coming on a set date, and that two of the three fixes carry the top severity rating. They can plan time to read the advisories and upgrade once the release is out. Vercel points security questions to [email protected].