Vercel / Next.js threat watch

Next.js application platform, deployment workflow, and Vercel service status watch.

Vendor watch hub

What this page covers

The Vercel / Next.jswatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Vercel / Next.js activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

83

Active

0

Featured

0

Unique CVEs

4

Most recent entry

May 21, 2026, 10:01 AM

Feed refreshes daily · 5:15 a.m. Central

Sources·Vercel status page (vercel-status.com)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent Vercel / Next.js watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

Elevated Build Errors

minor
resolvedStatus incident

We are currently investigating elevated build failures affecting a subset of Vite projects. Affected deployments may be timing out. We’ve identified an issue and are working on the fix.

May 21, 2026, 10:01 AMOfficial source

Missing Build CPU Minutes Usage Data

minor
resolvedStatus incident

We've identified an issue where some users may see missing Build CPU Minutes data on Usage pages in the Vercel Dashboard. The issue has been resolved, and we are backfilling the affected usage data.

May 20, 2026, 3:07 PMOfficial source

Increased Function Invocation Errors - ERR_MODULE_NOT_FOUND

minor
resolvedStatus incident

We're investigating an issue where customers are currently experiencing application failures due to function invocation errors when using React Router 7.

May 18, 2026, 4:42 PMOfficial source

Support cases cannot be submitted

minor
resolvedStatus incident

We are investigating an issue where support cannot be submitted through the dashboard.

May 18, 2026, 10:00 AMOfficial source

ai vulnerability (CVE-2026-8768)

MEDIUM
watchNVDCVE-2026-8768

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

May 17, 2026, 6:17 PMOfficial source

ai vulnerability (CVE-2026-8767)

LOW
watchNVDCVE-2026-8767

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

May 17, 2026, 6:17 PMOfficial source

turborepo language server protocol vulnerability (CVE-2026-46508)

HIGH
watchNVDCVE-2026-46508

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious workspace could provide crafted values through workspace settings or task names in the repository's source code that were interpolated into shell commands. When the extension activated or when a user ran a task through the extension, those values could be interpreted by the user's shell, allowing arbitrary command execution with the privileges of the local VS Code process. This vulnerability is fixed in 2.9.14000.

May 15, 2026, 11:16 AMOfficial source

turborepo vulnerability (CVE-2026-45772)

NONE
watchNVDCVE-2026-45772

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection executed yarn --version from the project directory, which could cause Yarn to load and execute a project-controlled yarnPath from .yarnrc.yml. An attacker who controls repository contents could cause code execution when a user or CI system runs affected turbo, @turbo/codemod, or @turbo/workspace conversion commands. This vulnerability is fixed in 2.9.14.

May 15, 2026, 11:16 AMOfficial source

Workflow usage amounts are incorrectly calculated

minor
resolvedStatus incident

Workflow Storage Retention and Workflow Storage Writes are being incorrectly calculated in usage data. The team is investigating and working to resolve the discrepancy.

May 15, 2026, 5:34 AMOfficial source

Vercel Queues, and Vercel Workflow runs were delayed

minor
resolvedStatus incident

Between 1:30 to 3:44 UTC, messages in Vercel Queues in iad1 were enqueued but not processed, and Vercel Workflows were blocked from making progress (i.e. remaining in pending / active states). This is recovering, Vercel Queues backlogs are being processed, and Vercel Workflows are unblocked.

May 8, 2026, 11:45 PMOfficial source

SSL Certificate Generation Delays

none
resolvedStatus incident

Between 18:36 and 19:04 UTC, issuing SSL certificates was delayed for new domains. These certificates have now been issued. Certificate renewals were not affected.

May 8, 2026, 2:15 PMOfficial source

Delays Processing Builds

minor
resolvedStatus incident

We've identified an issue where some customers may experience delays in builds starting and/or builds stuck in an initializing state. We are applying a fix and will provide additional updates as they become available.

May 8, 2026, 11:30 AMOfficial source

Elevated errors across multiple services in IAD1 (Washington, D.C., USA)

minor
resolvedStatus incident

Some Vercel functions that run in the IAD1 region are experiencing elevated invocation failures. We are investigating the issue and will share more information as it becomes available.

May 7, 2026, 8:18 PMOfficial source

Elevated Errors Creating New Deployments

minor
resolvedStatus incident

We are investigating an issue affecting new deployments that are stuck in the provisioning state. We will share more information as it becomes available.

May 7, 2026, 4:14 PMOfficial source

Increased error rate in Workflows

major
resolvedStatus incident

We are experiencing increased error rates with Workflows running on Vercel. We have identified the issue and are implementing a fix.

May 5, 2026, 6:30 PMOfficial source

Failures to load data across multiple services on the Vercel dashboard, API, and CLI

minor
resolvedStatus incident

We've identified an issue where various services in the Vercel dashboard, API, and CLI are failing to load data. These services include Observability, Speed Insights, Alerts, Usage, Web Analytics, Firewall, and CDN observability. Broadly, areas backed by analytical data are affected. We have identified the issue and are working on a fix. Production applications running on Vercel are not impacted.

May 5, 2026, 10:15 AMOfficial source

Request Failures in ICN1 (Seoul, South Korea)

major
resolvedStatus incident

Between 21:45–21:52 UTC, some users may have experienced request failures in ICN1. The issue has been identified, a fix has been applied, and the issue has been resolved.

May 4, 2026, 5:26 PMOfficial source

Elevated Functions Invocation Errors in ICN1 (Seoul, South Korea) Region

none
resolvedStatus incident

Between May 1, 11:01 am – May 1, 11:09 am UTC, users may have seen increased function invocation errors for traffic originated near the ICN1 Vercel CDN region. Requests to static assets/cached content were unaffected this time. We have reverted the change that caused the issue to mitigate this.

May 1, 2026, 6:30 AMOfficial source

Elevated Build Errors

minor
resolvedStatus incident

We are currently investigating this issue.

Apr 30, 2026, 1:57 PMOfficial source

Elevated Build Errors for Secure Compute/Static IPs Projects

minor
resolvedStatus incident

We are currently investigating this issue.

Apr 30, 2026, 12:30 PMOfficial source

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the Vercel / Next.js threat watch page?

It is the Vercel / Next.js-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Vercel / Next.js watch page?

Use it to confirm whether current Vercel / Next.js issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Vercel / Next.js security issues?

Yes. ITECS can help map Vercel / Next.js advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.