Vercel has pre-announced a Next.js security release for 30 September with nine fixes, one of them critical. If an agency built your site on Next.js and walked away, this is the week to find out who patches it.
Vercel, the company behind Next.js, has pre-announced a scheduled security release for 30 September 2026. It covers nine vulnerabilities across the framework, one of which is rated critical. Fixed versions will be Next.js 16.3.7 and Next.js 15.5.27. A separate, unscheduled fix for the next/og image package already shipped on 22 September.
Pre-announcing a patch is what responsible projects do: it gives the people who run Next.js sites a week to line up a maintenance window. It also tells attackers that something worth exploiting is about to be documented. Sites that are still unpatched a few weeks after 30 September are the ones that get hit.
Next.js is the framework behind a large share of the business websites built in the last three years, including most of the ones we ship for clients in the UAE, the UK and Pakistan. It is a good choice, and this release does not change that. Every serious framework has security releases. What matters is whether anyone is going to apply this one to your site.
Here is the uncomfortable pattern we see. A business pays an agency for a website. The site launches. The agency's involvement ends. Two years later the site is still running the version of Next.js it launched with, and nobody has an account on the server. That site will not be patched on 30 September, or ever.
You do not need a developer for this step.
_next/.If you see it, your site runs Next.js. To find which version, ask whoever hosts the site for the next line in the package.json file. Anything on the 15.x line below 15.5.27, or the 16.x line below 16.3.7, needs the update on 30 September.
If you are hosted on Vercel and have automatic deployments from a repository, the update still does not happen by itself. Someone has to bump the version and deploy.
If you have a maintenance contract: send your provider this post and ask them to confirm, in writing, when the update will be applied. A same-week answer is reasonable for a critical fix.
If your developer is a freelancer who has moved on: you need access to the code repository and the hosting account before the 30th. Ask for both now. If they cannot give you either, that is a bigger problem than this patch.
If you do not know who maintains your site: that is the most common answer, and it is fixable. We take over Next.js sites we did not build. The first step is a free 15-minute check where we confirm the version, the hosting and whether anything else is out of date.
For a well-built site the patch is routine: update one dependency, run the build, deploy, check the key pages. An hour of work, sometimes less. It is not a redesign and it does not change how the site looks.
Where it gets harder is a site that has not been updated in a long time. Jumping several major versions of Next.js can break things, and the fix becomes a small project rather than a patch. That is one reason we put every site we build on a maintenance plan from day one: keeping a site current costs far less than catching it up.
We keep client sites patched as part of our cloud and DevOps service, from $300 a month (about AED 1,100 or £240), which also covers hosting, backups, uptime monitoring and speed checks. For a small marketing site that does not need the full plan, a one-off update and security review is a fixed $150.
We will update this post on 30 September with the published list of vulnerabilities.
Not sure whether your site is affected or who looks after it? Book a free 15-minute check and we will tell you before the patch lands.
We build the systems described in this article. Let’s talk about your project.
Keep reading