Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution
ID: 282a77d5-a8e2-5f0c-87b9-4d3062d2f9fd
STIX ID: report--282a77d5-a8e2-5f0c-87b9-4d3062d2f9fd
Feed Name: CISecurity.org Advisories
Multiple critical vulnerabilities were disclosed in NGINX (CVE-2026-42945, CVE-2026-42946, CVE-2026-40701, CVE-2026-42934) including a heap buffer overflow that can enable remote code execution when ASLR is disabled, an excessive memory allocation that can crash workers, a use-after-free in TLS OCSP handling, and an out-of-bounds read in charset handling; successful exploitation can crash NGINX worker processes and, in some configurations, allow unauthenticated RCE, so operators should prioritize patching or mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
