THREAT OPS › Threat News › [GHSA] GHSA-p293-qw3h-jr36 (critical) — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
[GHSA] GHSA-p293-qw3h-jr36 (critical) — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-p293-qw3h-jr36 Severity: critical CVE: CVE-2026-75604
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
## Impact
A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.
## Workaround
There is no known workaround for affected windows-hosted
Indicators of compromise
- CVE-2026-75604cve
Original source: https://github.com/advisories/GHSA-p293-qw3h-jr36