Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A high-severity authentication bypass vulnerability (CVE-2026-44575, CVSS 8.2) affects Next.js applications using the App Router, allowing attackers to circumvent middleware-enforced authentication and authorization controls. Any organization running Next.js-based web applications, including customer portals, APIs, and internal tools built on this framework, may be exposing protected resources to unauthenticated access. Cloudflare deployed an emergency WAF rule on 2026-05-07 for this vulnerability, suggesting active exploitation risk; organizations using Cloudflare should activate this rule immediately.

Author

Tech Jacks Solutions