This emergency release introduces a new rule to detect Next.js App Router middleware and proxy bypass attempts via segment-prefetch routes (CVE-2026-44575).
Key Findings
CVE-2026-44575: Next.js Middleware / Proxy Bypass in App Router Applications via Segment-Prefetch Routes
Successful exploitation allows unauthenticated attackers to bypass middleware or proxy-based authorization checks in affected Next.js App Router applications. This leads to unauthorized access to protected content, potential exposure of sensitive application data, and compromise of application security boundaries.
We strongly recommend upgrading to Next.js 15.5.16 or 16.2.5 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, enforce authorization in the underlying route or page logic instead of relying solely on middleware.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 1de95bf6d6374e1099854278e77e4a53 | N/A | Next.js – Middleware Bypass via Invalid RSC Header – CVE:CVE-2026-44575 | N/A | Disabled | This is a new detection. |
Source: Cloudflare
Latest Posts
- Power Apps- Enhance row summaries in model-driven apps [MC1324999]
![Power Apps- Enhance row summaries in model-driven apps [MC1324999] 2 pexels jplenio 1119973](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Power Automate – Configure notifications for desktop flow checker in admin portal [MC1324990]
![Microsoft Power Automate - Configure notifications for desktop flow checker in admin portal [MC1324990] 3 pexels ekamelev 1685594](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Power Automate – View property value expanded inline in the new cloud flow designer [MC1324868]
![Power Automate - View property value expanded inline in the new cloud flow designer [MC1324868] 4 pexels verma harshil 3103199](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Power Automate – Export object-centric process mining data to Microsoft Fabric semantic model [MC1325013]
![Microsoft Power Automate - Export object-centric process mining data to Microsoft Fabric semantic model [MC1325013] 5 pexels goumbik 1414130](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Power Apps- Enhance row summaries in model-driven apps [MC1324999] 2 pexels jplenio 1119973](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-jplenio-1119973-150x150.webp)
![Microsoft Power Automate - Configure notifications for desktop flow checker in admin portal [MC1324990] 3 pexels ekamelev 1685594](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-ekamelev-1685594-150x150.webp)
![Power Automate - View property value expanded inline in the new cloud flow designer [MC1324868] 4 pexels verma harshil 3103199](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-verma-harshil-3103199-150x150.webp)
![Microsoft Power Automate - Export object-centric process mining data to Microsoft Fabric semantic model [MC1325013] 5 pexels goumbik 1414130](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-goumbik-1414130-150x150.webp)
