Showing the 20 most recent items, newest first. Each row links to the official advisory.
20 rows · sorted newest first
Operations view
Increased invocation failures for Hobby Team functions
minor
resolvedStatus incident
There are elevated rates of invocation failures for Hobby Team functions in new deployments. Existing deployments are unaffected. We are investigating. Mitigation is possible by rolling back to a previous deployment.
GitHub-linked deployments and authentication affected
minor
resolvedStatus incident
We are investigating elevated error rates for users logging in to Vercel using their GitHub account and connecting their GitHub accounts to Vercel. Login with email or other sign-in methods is unaffected.
We are investigating SAML Single Sign-On (SSO) errors, leading to inability to login using SAML/SSO or access SSO-protected teams through the Vercel dashboard and CLI.
We've identified an issue where some users may see missing Build CPU Minutes data on Usage pages in the Vercel Dashboard. The issue has been resolved, and we are backfilling the affected usage data.
We have identified an increase in erroneous 2FA (two-factor authentication) challenges and errors when accessing the Vercel dashboard and multiple API services for teams that require 2FA. We will share more information once we have it.
We've identified an issue where some customers may experience failed Builds beginning at 21:05 UTC.
A rollback is in progress to mitigate this issue. We will provide additional updates as they become available.
Failed deployments can be retried and should succeed.
We've identified an issue where some customers may receive erroneous spend management budget notifications due to a spend management budget miscalculation. Affected teams with spend management budgets configured to pause projects may also experience paused deployments. We are currently investigating this issue. We will provide additional updates as they become available.
The issue affecting Build Logs has been resolved. Between Jul 8 19:05 UTC and Jul 9 13:16 UTC, some Pro customers using standard machine types may have experienced missing Build Logs.
New builds after the impact period are unaffected.
We've identified an issue where some customers may experience delays in builds starting and/or builds stuck in an initializing state. We are currently investigating this issue and will provide additional updates as they become available.
Degraded performance on CDN, Dashboard, Functions in Washington, Cleveland (iad1, cle1)
minor
resolvedStatus incident
We are investigating an issue causing degraded performance across CDN, Dashboard, & Functions in Washington, Cleveland (iad1, cle1). We'll provide additional updates as they become available.
Increase in Workflow runs stuck in pending, failed
minor
resolvedStatus incident
We've identified an issue where some workflow runs created between June 30 at 22:24 UTC and July 1 at 16:08 UTC may be stuck in a pending state or have reached a failed state.
New workflow runs are not impacted. We are working on a fix for runs stuck in a pending state and will provide additional updates as they become available.
We are currently investigating an issue where some recently deployed Workflow projects are stuck as pending and not delivering queued messages as expected.
Resolved: Elevated ERR_STREAM_PREMATURE_CLOSE errors in Vercel Functions
none
resolvedStatus incident
Between Jun 19 09:09 and 16:16 UTC, a subset of Vercel Functions using node-fetch@2 may have experienced intermittent invocation errors that surfaced as ERR_STREAM_PREMATURE_CLOSE.
As part of Node.js June 2026 security releases, we began rolling out new Node.js versions. Those versions contain an upstream regression that breaks response streaming for node-fetch@2, which caused the errors https://github.com/nodejs/node/issues/63989
We have resolved the issue by reverting to the previous Node.js version. No action is required — affected functions are now operating normally. We will re-land the Node.js upgrade once the upstream issue is fixed.
Elevated Functions Invocation Errors in DUB1 (Dublin, Ireland) Region
minor
resolvedStatus incident
The issue has been identified and a fix is being implemented.
A small number of requests may have seen elevated error rates in function invocations during this period.
We are investigating reports of some customers experiencing elevated errors creating new deployments. We will provide additional updates as they become available.
Increased invocation failures for Hobby Team functions
There are elevated rates of invocation failures for Hobby Team functions in new deployments. Existing deployments are unaffected. We are investigating. Mitigation is possible by rolling back to a previous deployment.
Functions
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
GitHub-linked deployments and authentication affected
We are investigating elevated error rates for users logging in to Vercel using their GitHub account and connecting their GitHub accounts to Vercel. Login with email or other sign-in methods is unaffected.
Dashboard
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We are investigating SAML Single Sign-On (SSO) errors, leading to inability to login using SAML/SSO or access SSO-protected teams through the Vercel dashboard and CLI.
SAML Single Sign-On
major
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We've identified an issue where some users may see missing Build CPU Minutes data on Usage pages in the Vercel Dashboard. The issue has been resolved, and we are backfilling the affected usage data.
Builds
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We have identified an increase in erroneous 2FA (two-factor authentication) challenges and errors when accessing the Vercel dashboard and multiple API services for teams that require 2FA. We will share more information once we have it.
Dashboard
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We've identified an issue where some customers may experience failed Builds beginning at 21:05 UTC.
A rollback is in progress to mitigate this issue. We will provide additional updates as they become available.
Failed deployments can be retried and should succeed.
Builds
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We've identified an issue where some customers may receive erroneous spend management budget notifications due to a spend management budget miscalculation. Affected teams with spend management budgets configured to pause projects may also experience paused deployments. We are currently investigating this issue. We will provide additional updates as they become available.
Dashboard
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
The issue affecting Build Logs has been resolved. Between Jul 8 19:05 UTC and Jul 9 13:16 UTC, some Pro customers using standard machine types may have experienced missing Build Logs.
New builds after the impact period are unaffected.
Next.js / Vercel
none
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We've identified an issue where some customers may experience delays in builds starting and/or builds stuck in an initializing state. We are currently investigating this issue and will provide additional updates as they become available.
Builds
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
Degraded performance on CDN, Dashboard, Functions in Washington, Cleveland (iad1, cle1)
We are investigating an issue causing degraded performance across CDN, Dashboard, & Functions in Washington, Cleveland (iad1, cle1). We'll provide additional updates as they become available.
Dashboard
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
Increase in Workflow runs stuck in pending, failed
We've identified an issue where some workflow runs created between June 30 at 22:24 UTC and July 1 at 16:08 UTC may be stuck in a pending state or have reached a failed state.
New workflow runs are not impacted. We are working on a fix for runs stuck in a pending state and will provide additional updates as they become available.
Workflow
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We are currently investigating an issue where some recently deployed Workflow projects are stuck as pending and not delivering queued messages as expected.
Workflow
major
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
Resolved: Elevated ERR_STREAM_PREMATURE_CLOSE errors in Vercel Functions
Between Jun 19 09:09 and 16:16 UTC, a subset of Vercel Functions using node-fetch@2 may have experienced intermittent invocation errors that surfaced as ERR_STREAM_PREMATURE_CLOSE.
As part of Node.js June 2026 security releases, we began rolling out new Node.js versions. Those versions contain an upstream regression that breaks response streaming for node-fetch@2, which caused the errors https://github.com/nodejs/node/issues/63989
We have resolved the issue by reverting to the previous Node.js version. No action is required — affected functions are now operating normally. We will re-land the Node.js upgrade once the upstream issue is fixed.
Functions
none
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
Elevated Functions Invocation Errors in DUB1 (Dublin, Ireland) Region
The issue has been identified and a fix is being implemented.
A small number of requests may have seen elevated error rates in function invocations during this period.
Functions
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
We are investigating reports of some customers experiencing elevated errors creating new deployments. We will provide additional updates as they become available.
Builds
minor
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. No EPSS.
The Vercel / Next.jswatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent Vercel / Next.js activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
108
Active
0
Featured
0
Unique CVEs
0
Most recent entry
Jul 17, 2026, 9:12 AM
Feed refreshes daily · 5:15 a.m. Central
Sources·Vercel status page (vercel-status.com)
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
It is the Vercel / Next.js-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the Vercel / Next.js watch page?
Use it to confirm whether current Vercel / Next.js issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to Vercel / Next.js security issues?
Yes. ITECS can help map Vercel / Next.js advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.