#9
The Hacker News
general
July 19, 2026 at 20:42 UTC
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
By [email protected] (The Hacker News)
AI Summary
F5 patched CVE-2026-42533 on July 15, 2026 — a critical heap buffer overflow in NGINX worker processes triggerable by unauthenticated remote attackers via crafted HTTP requests — in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Given NGINX's ubiquity as a web server and reverse proxy, unpatched instances face potential crash or RCE risk from any external attacker.
Relevance score: 77.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →