Tweet by CloudflareDev

May 7, 2026

Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. https://t.co/mT9ujk1H7c

Author
CloudflareDev
Date
May 7, 2026