Next.js formalizes monthly security releases; July 20 patch scheduled
Key Points
- Monthly scheduled security releases
- July 20, 2026: patches for 16.2 & 15.5
- Fixes include 4 high and 5 medium issues
Summary
Vercel is formalizing a predictable security-release program for Next.js with roughly monthly, pre-announced updates. The first scheduled security release is planned for July 20, 2026 and will publish patches for Next.js 16.2 and 15.5. That release addresses multiple vulnerabilities (4 high, 5 medium). Urgent or actively exploited issues will still be released ad-hoc.
Key Points
- Monthly pre-announced security releases to improve planning and coordination with hosts and partners.
- First scheduled release: July 20, 2026 — patches for Next.js 16.2 and 15.5; includes fixes for 4 high and 5 medium severity vulnerabilities.
- Ad-hoc releases will continue for critical/actively exploited vulnerabilities.
- Blog posts will include timelines and the highest anticipated severity; CVE details will be published with the patch.
- Security program: Vercel Open Source Bug Bounty and internal research; contact security@vercel.com for questions.
Recommended actions for engineers
- Monitor the Next.js blog for the July 20 post and CVE details; plan upgrades accordingly.
- Stage and test the 16.2/15.5 patches once published; prioritize high-severity fixes.
- If immediate patching isn’t possible, coordinate with hosting providers and apply mitigations (firewall rules, WAF, network controls).
- Subscribe to announcements and consider participating in the Vercel bug bounty if you research vulnerabilities.