Home/News/Critical NGINX Vulnerability Patched, May Allow RCE
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Critical NGINX Vulnerability Patched, May Allow RCE

Critical NGINX Vulnerability Patched, May Allow RCE

F5 has released patches for a critical vulnerability affecting NGINX, identified as CVE-2026-42533. This flaw allows a remote, unauthenticated attacker to trigger a heap buffer overflow in the worker process by sending specially crafted HTTP requests. The successful exploitation of this vulnerability can lead to the crashing or restarting of NGINX worker processes, potentially causing a denial-of-service condition.

The security updates were deployed on July 15. Specifically, NGINX version 1.30.4 (stable branch) and 1.31.3 (mainline branch) now include the fix. Additionally, NGINX Plus version 37.0.3.1 has been updated to address this issue. F5 strongly advises all users running earlier builds of NGINX and NGINX Plus to upgrade to the patched versions as soon as possible to mitigate the risk of exploitation.

While the primary impact of exploiting CVE-2026-42533 is a denial-of-service through worker process termination, the vulnerability also carries the potential for remote code execution. This means that an attacker might be able to not only disrupt the service but also gain unauthorized control over the affected server. The specific conditions under which remote code execution can be achieved are still under investigation, but the severity of the potential consequences underscores the urgency of applying the provided security patches.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next