This emergency release introduces a new rule to detect Next.js App Router middleware and proxy bypass attempts via segment-prefetch routes (CVE-2026-44575).
Key Findings
CVE-2026-44575: Next.js Middleware / Proxy Bypass in App Router Applications via Segment-Prefetch Routes
Successful exploitation allows unauthenticated attackers to bypass middleware or proxy-based authorization checks in affected Next.js App Router applications. This leads to unauthorized access to protected content, potential exposure of sensitive application data, and compromise of application security boundaries.
We strongly recommend upgrading to Next.js 15.5.16 or 16.2.5 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, enforce authorization in the underlying route or page logic instead of relying solely on middleware.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 1de95bf6d6374e1099854278e77e4a53 | N/A | Next.js – Middleware Bypass via Invalid RSC Header – CVE:CVE-2026-44575 | N/A | Disabled | This is a new detection. |
Source: Cloudflare
Latest Posts
- WAF – WAF Release – 2026-05-07 – Emergency

- SharePoint News web part: New Filmstrip layout and multi-site news support [MC1303716]
![SharePoint News web part: New Filmstrip layout and multi-site news support [MC1303716] 3 pexels cottonbro 9668883](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Default compose font: Administrators can allow users to change the default font in Outlook for iOS and Android [MC1303717]
![Default compose font: Administrators can allow users to change the default font in Outlook for iOS and Android [MC1303717] 4 pexels digitalbuggu 519411](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings [MC1303719]
![Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings [MC1303719] 5 pexels padrinan 114108](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)


![SharePoint News web part: New Filmstrip layout and multi-site news support [MC1303716] 3 pexels cottonbro 9668883](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-cottonbro-9668883-150x150.webp)
![Default compose font: Administrators can allow users to change the default font in Outlook for iOS and Android [MC1303717] 4 pexels digitalbuggu 519411](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-digitalbuggu-519411-150x150.webp)
![Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings [MC1303719] 5 pexels padrinan 114108](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-padrinan-114108-150x150.webp)