logo

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

ID: 282a77d5-a8e2-5f0c-87b9-4d3062d2f9fd

STIX ID: report--282a77d5-a8e2-5f0c-87b9-4d3062d2f9fd

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

Multiple critical vulnerabilities were disclosed in NGINX (CVE-2026-42945, CVE-2026-42946, CVE-2026-40701, CVE-2026-42934) including a heap buffer overflow that can enable remote code execution when ASLR is disabled, an excessive memory allocation that can crash workers, a use-after-free in TLS OCSP handling, and an out-of-bounds read in charset handling; successful exploitation can crash NGINX worker processes and, in some configurations, allow unauthenticated RCE, so operators should prioritize patching or mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.