CVE-2026-0969
- CVSS
- —
- EPSS
- 0.006 (46.0th percentile)
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage
Vercel (blog + changelog)
New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by default
next-mdx-remote CVE-2026-0969 Any new deployment containing a version of the third-party packagethat is vulnerable towill now automatically fail to deploy on Vercel. We strongly recommend upgrading to a patched version regardless of your hosting provider…
What we observed
No signals recorded