Netlify changed its API changelog
API changeloghttps://netlify.com/changelog
ChangeAPI changelog
New security advisory added for two critical Next.js vulnerabilities (CVE-2026-75604 and GHSA-2xp9-vwfh-vxw4) requiring upgrade to versions 15.5.24 or 16.3.3; unrelated Agent Runners feature announcement removed.
CHANGELOG
All Tags Agent-runners AI Ai-gateway Angular Astro AX Build CLI Database Design Devtools Domains E-commerce Extensions Forms Framework Functions Logs Next.js Nuxt.js Remix SDK Security Updates Workflow Subscribe to feed
* PRE-LAUNCH TOOLBAR AND THE POWERED BY NETLIFY BADGE
CHANGELOG
All Tags Agent-runners AI Ai-gateway Angular Astro AX Build CLI Database Design Devtools Domains E-commerce Extensions Forms Framework Functions Logs Next.js Nuxt.js Remix SDK Security Updates Workflow Subscribe to feed
* SECURITY UPDATE: TWO CRITICAL NEXT.JS VULNERABILITIES
August 25, 2026
* security
* next.js
The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution. Both are patched in 15.5.24 and 16.3.3.
Confidence95%
Full diff
===================================================================
--- before
+++ after
@@ -1,8 +1,50 @@
CHANGELOG
All Tags Agent-runners AI Ai-gateway Angular Astro AX Build CLI Database Design Devtools Domains E-commerce Extensions Forms Framework Functions Logs Next.js Nuxt.js Remix SDK Security Updates Workflow Subscribe to feed
+ * SECURITY UPDATE: TWO CRITICAL NEXT.JS VULNERABILITIES
+
+ August 25, 2026
+
+ * security
+ * next.js
+
+ The Next.js team has disclosed two critical severity vulnerabilities, both of which can lead to unauthenticated remote code execution. Both are patched in 15.5.24 and 16.3.3. Netlify-hosted sites are not affected by the Windows issue, and do not run the Next.js code path affected by the image issue. We still recommend upgrading. Here’s what Netlify customers need to know.
+
+
+ VULNERABILITIES
+
+ VulnerabilitySeverityAffected versionsCVE-2026-75604 / GHSA-p293-qw3h-jr36 — Unauthenticated remote code execution on Windows-hosted serversCritical≥13.4.0 <15.5.24, ≥16.0.0 <16.3.3GHSA-2xp9-vwfh-vxw4 — Unauthenticated remote code execution in Image Optimization API when AVIF files are usedCritical≥10.0.0 <15.5.24, ≥16.0.0 <16.3.3
+
+
+ IMPACT ON NETLIFY
+
+
+ UNAUTHENTICATED REMOTE CODE EXECUTION ON WINDOWS-HOSTED SERVERS
+
+ CVE-2026-75604 / GHSA-p293-qw3h-jr36: Netlify sites are not affected. The issue affects Windows-hosted deployments only, and Netlify Functions and Edge Functions run on Linux.
+
+
+ UNAUTHENTICATED REMOTE CODE EXECUTION IN IMAGE OPTIMIZATION API WHEN AVIF FILES ARE USED
+
+ GHSA-2xp9-vwfh-vxw4: Netlify sites do not run the affected Next.js code path. Requests to /_next/image are rewritten to Netlify Image CDN at our edge, so the Next.js Image Optimization API is never invoked.
+
+
+ WHAT SHOULD I DO?
+
+ Netlify sites are not affected by the Windows issue and do not run the affected image code path, but we always strongly recommend upgrading as soon as possible to patched releases:
+
+ * next 15.5.24 or later, or 16.3.3 or later, then redeploy.
+
+
+ RESOURCES
+
+ * Next.js August 2026 security release
+ * Next.js security advisories
+
+ Permalink to Security Update: Two critical Next.js vulnerabilities Permalink
+
* PRE-LAUNCH TOOLBAR AND THE POWERED BY NETLIFY BADGE
August 19, 2026
@@ -258,53 +300,6 @@
To learn more about using AI Gateway, check out our official AI Gateway Netlify docs.
Permalink to AI Gateway adds OpenRouter support for more AI model choice Permalink
- * AGENT RUNNERS ADDS OPENCODE AND AI MODEL CONTROLS
-
- August 6, 2026
-
- * agent runners
- * ai
-
- Through a new partnership with OpenRouter, you can now choose OpenCode as an AI agent with Agent Runners. OpenCode allows you to choose many different AI models, including Kimi, DeepSeek, and GLM.
-
- Learn more about our OpenRouter partnership through the Netlify blog on open models.
-
- Previously, you could only choose Claude, Gemini, or Codex as your AI agent, but now you can choose the OpenCode agent, which offers even more models from different AI providers.
-
- Requests made through OpenCode are only routed to model providers with a Zero Data Retention (ZDR) policy, so your prompts and outputs are never stored.
-
-
- AI MODEL SELECTION
-
- As part of this release, you can now also specify which model any agent uses with Agent Runners. Previously, Claude, Gemini, and Codex agents all automatically chose a model for the task you prompted with Agent Runners.
-
- Agents can still auto-select a model for you, but now you can also choose different models for your agents, with these preferences saved just for you on your device.
-
- This means you can experiment with which AI models best fit your needs.
-
- To open your AI model options for Agent Runners, select agent near your prompt box.
-
-
- CHOOSING THE BEST AI MODEL FOR YOUR NEEDS
-
- To help you choose the best AI model for your needs, within Agent Runners you can browse details about each model, including a link to learn more, a visual way to compare cost across all supported models with a 1-5 dot scale, and the option to set an effort level for that model.
-
- To get the most out of your credits, consider the following strategies:
-
- * Use a more expensive, capable model to help you plan your project updates and design a clear prompt with Agent Runners’ ask mode, then switch to a cheaper model to implement the changes.
- * Experiment with using different AI models for different tasks.
- * Be explicit about the functionality you want when using models that are cheaper or set to a lower effort level. These models may fill in placeholder functionality. For example, a model might render a contact page without fully setting up working Netlify Forms, so the page looks complete but doesn’t actually work as expected.
-
-
- LEARN MORE
-
- To learn more, check out our docs:
-
- * Agent Runners overview
- * Make changes with Agent Runners
-
- Permalink to Agent Runners adds OpenCode and AI model controls Permalink
-
Next page
Ask Netlify
\ No newline at end of file
Get the next one in your inbox.
Follow the vendor for free, or write your own prompt and watch any page the same way.