Next.js 16.3.8 and 15.5.27 fix nine vulnerabilities, one critical
Next.js published 16.3.8 and 15.5.27 on September 30, 2026 as a scheduled security release covering nine vulnerabilities: one critical, two high, five medium and one low. The 15.5 line receives the backported fixes. The 16.3.7 release on September 29 was a bug fix only and does not include them.

Why it matters
This is the second Next.js security release in eight days, and both maintained lines are affected.
Who should care
Every Next.js 15 and 16 app
What you can do
Upgrade to 16.3.8 or 15.5.27 and read the advisories for which of the nine apply to your routes.

