Home / Jul 21, 2026 / Story
0
#9 The Hacker News general July 19, 2026 at 20:42 UTC

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

By [email protected] (The Hacker News)

AI Summary

F5 patched CVE-2026-42533 on July 15, 2026 — a critical heap buffer overflow in NGINX worker processes triggerable by unauthenticated remote attackers via crafted HTTP requests — in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Given NGINX's ubiquity as a web server and reverse proxy, unpatched instances face potential crash or RCE risk from any external attacker.

Relevance score: 77.0/100

# More from July 21