Next.js 16.4 Is Out and Another Security Patch Lands October 14: What You Should Do Now

8 min read

If your website or app runs on Next.js, the last three weeks have been busy. There were two security releases in September, a new version (16.4) came out on October 6, and the Next.js team has already announced another security update for October 14 that fixes two Critical issues.

Most founders don't read framework release notes, and that's fine. But you should know enough to ask your developer the right question this week. So here is a simple breakdown of what happened and what we would do right now.

First, the short version

  • If your app is on Next.js 16, it should be on 16.3.8 or newer (16.4.0 is the latest stable release right now).
  • If your app is on Next.js 15, it should be on 15.5.27.
  • On October 14, 2026, the Next.js team plans to release another out-of-band security update for two Critical and one High issue. Keep some time free that week to update again.
  • Next.js 16.4 is a good release, but you don't need to rush its new features. The security patches are the urgent part.

What happened in September

September 22: a critical fix for social share images

Next.js released 16.3.6 and 15.5.26 as an out-of-band (unscheduled) update. The main issue was in next/og, the feature many sites use to generate those preview images you see when a link is shared on WhatsApp, LinkedIn or X.

The official advisory rated it Critical. Under specific conditions, improper escaping in SVG output from Satori (the library behind these images) could lead to remote code execution, because of problems in other upstream dependencies. In simple words, in the worst case someone could run their own code on your server.

A few details matter here:

  • Only Next.js versions from 16.2.0 up to (but not including) 16.3.6 were affected by the remote code execution issue.
  • Only the Node.js version of ImageResponse was affected. Apps using the Edge version were not.
  • Next.js 15 was not affected by the RCE itself, but 15.5.26 got some related hardening.

September 30: seven more fixes

A week later came the scheduled September security release: 16.3.8 and 15.5.27. This one fixed seven issues. The one rated High was a server-side request forgery problem in Image Optimization.

If your next.config file has images.remotePatterns set up (very common if you load images from a CMS, S3 bucket or any other domain), an attacker-controlled URL that matches one of those allowed patterns could make your server fetch things it shouldn't, like private IP addresses. If you don't use remotePatterns at all, this one doesn't affect you.

The other six were rated Medium or Low. A few that are worth understanding even if you're not technical:

  • Cache poisoning on SSG and ISR pages. In certain setups, one crafted request could make a cached page show the wrong content to every visitor until it's regenerated.
  • Draft content leaking. If you preview unpublished CMS content with Draft Mode and have Cache Components (use cache) turned on, a normal visitor could receive that unpublished content, and it could even get saved into the generated page.
  • The dev server's MCP endpoint. This one is rated Low, but it's interesting. next dev exposes a Model Context Protocol endpoint, the thing AI coding agents use to talk to your running app. It wasn't checking which website a request came from. So a malicious site that your developer opened in their browser while the dev server was running could read things like the project's folder path, code snippets from error reports, the list of routes and development logs. Production sites never serve this endpoint, so your live website was not exposed through it. But it's a good reminder that AI tooling inside the dev setup is now part of your security surface too.

What's coming on October 14

When the September 30 release went out, the Next.js team said that fixes for one Critical and one High issue had to be postponed because of delays in an upstream dependency.

Now they have announced an out-of-band security update for Wednesday, October 14, 2026. According to their post, it will fix three vulnerabilities in upstream dependencies: two Critical and one High. Two of these are the ones postponed from September.

The full details, affected versions and upgrade steps will only be published with the update. That's normal practice, so attackers don't get a head start.

So don't treat this as a one-time update. Plan for one more next week, and make sure someone owns doing it on the day.

So what is new in Next.js 16.4?

Not everything this month is about security. Next.js 16.4, released on October 6, is a meaningful release, especially for new projects.

Cache Components are now the recommended way

The big message from the Next.js team is that Cache Components are now recommended for every Next.js app. All new apps created with create-next-app have them turned on by default, and they will become the default in Next.js 17.

In plain words, developers mark specific parts of a page as cacheable with a 'use cache' line, instead of Next.js guessing what to cache. So one page can have a cached product list and a live, personalised header. If you've ever heard "the page is showing old data because of caching", this model is meant to make that more predictable.

Tools to keep pages static

There is a new ensureStatic option. A developer can add it to a page or layout, and the build will fail if someone accidentally adds something dynamic to it. For marketing sites, blogs and ecommerce stores, this is useful because dynamic pages cost more server compute. It's a simple guard against surprise hosting bills.

Upgrades with an AI agent

This part is new. Next.js 16.4 adds a next upgrade --agent command that prepares migration guides, codemods and verification steps for a coding agent, so the agent can do the upgrade and check that the app still works.

There is also an experimental agentUpgrade setting. Its default policy, 'security', reminds you or your agent when an upgrade is available that fixes known vulnerabilities in your installed version, while you run next dev or next build. After the month Next.js has had, good timing.

What we would do this week

At Krishiv Labs, this is roughly the checklist we follow when something like this happens. You can share it directly with your developer.

  1. Check the version. Open package.json and see which next version is installed. Also check the lock file, because that is what actually gets deployed.
  2. Patch first, upgrade later. If you're on 16.x, move to at least 16.3.8. If you're on 15.x, move to 15.5.27. Don't mix a security patch with a big feature upgrade in the same deploy. Moving to 16.4 is fine, but treat it as its own change and test it properly.
  3. Look at older versions seriously. The September patches were only released for the 16.3 and 15.5 lines. If your app is on something older than that, it's time to plan an upgrade, not just a patch.
  4. Check your image config. If you use images.remotePatterns, keep the allowed domains as tight as possible. Allow only the exact hosts you need.
  5. Block time for October 14. Put it on the calendar. Once the advisories are out, read which versions are affected and update the same day if your app is on that list.
  6. Turn on Dependabot or Renovate. These tools open a pull request automatically when a dependency has a security fix. Small effort, big help.
  7. Check other dependencies too. Run npm audit (or your package manager's equivalent) after updating Next.js.

If you're on Vercel, a few of these issues don't affect you, as the advisories mention. But most fixes still have to go into your code, so don't skip the update.

A small note on AI coding tools

We use AI coding tools a lot, and they are great at writing features. But they won't patch your dependencies after launch unless someone sets that up. The new next upgrade --agent command helps, but a human still needs to own the job of "keep this app patched".

That's the real lesson from this month. Launching the app is one part of the work. Keeping it updated is the part people forget.

Conclusion

Next.js is still a great choice for web apps, and 16.4 makes it better. But September showed that popular frameworks get serious security fixes often, sometimes back to back.

So this week: update to 16.3.8+ or 15.5.27, plan for the October 14 update, and decide who in your team owns these updates going forward. If you don't have someone for that, at least make sure your developer or agency has it in their monthly maintenance.

Sources: Next.js security update, September 22, Next.js September 2026 security release, Upcoming Next.js security update, October 2026, Next.js 16.4 release post.