Next.js Security Patch Due Today, Docker Desktop 4.93

Executive summary
Next.js: a coordinated security release (16.3.8 and 15.5.27) covering nine vulnerabilities, one critical, is scheduled for today. See the Vercel announcement.
Next.js: v16.3.7 shipped yesterday with a Turbopack fix for a hanging strongly consistent read on a canceled task.
Docker Desktop 4.93.0 (Sept 28) closes a VM-side Unix socket port forward flaw, addresses containerd CVE-2026-53495, and ships Engine v29.8.1. Details in the release notes.
Node.js: v26.10.0 (Current) and v22.23.3 (LTS) landed in the last week.
Next.js: nine fixes due today, upgrade first to 16.3.6
Vercel's pre-announcement lists one critical, two high, five medium and one low severity issue, fixed in 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS). Details are embargoed until release, so the immediate action is to be on a patched baseline and ready to bump.
The out-of-band September 22 update already fixed a critical upstream issue, and 16.3.6 fixed a remote code execution bug in next/og ImageResponse (GHSA-vcvr-r3jv-pc5j). If you are below 16.3.6 or 15.5.26, stop and upgrade now.
# Check what you run
npm ls next
# Move to the current patched line, then to 16.3.8 once published
npm install [email protected]
npm install [email protected] # after today's releaseOn the canary channel, v16.4.0-canary.53 enables Cache Components by default in create-next-app, and recent canaries surface security upgrade insights in DevTools and drop the unstable_ prefix from some navigation APIs. Treat canaries as previews, not production targets.
Docker Desktop 4.93.0: isolation and containerd fixes
The 4.93.0 release notes describe a fix for an issue where code inside the VM could request Unix socket port forwards and manipulate arbitrary host paths. Enhanced Container Isolation enforcement was also tightened, and the Linux kernel moved to v7.0.14, restoring MongoDB 8 startup. Bundled components include Docker Engine v29.8.1.
The prior 4.92.0 release updated containerd to v2.3.5 for security, and the 4.93.0 cycle references CVE-2026-53495 in containerd. Verify against the NVD record for affected ranges. Windows admins get a fixed MSI that adds users to the docker-users group, plus a fix for a startup crash (exit code 151) on config files with a UTF-8 BOM.
docker version --format '{{.Server.Version}}'
# expect 29.8.1 after updating Docker Desktop to 4.93.0Node.js: new Current and LTS builds
The Node.js release blog lists v26.10.0 (Current, Sept 22) and v22.23.3 (LTS, Sept 23), following v24.21.0 (LTS) and v26.8.2 on Sept 9. Pin your runtime in CI and read the changelog for your line before rolling forward.
# Dockerfile
FROM node:24-alpine # pin to your LTS line and rebuild to pick up patchesCoverage note
Other tools on the watchlist (Keycloak, Cloudflare, Nuxt, Prisma, Drizzle, PostgreSQL and more) had no verifiable notable release in today's audit sources, so they are omitted rather than padded. Every link above points to an official release page, advisory or CVE record.
Comments
Share your thoughts and join the conversation



