logo

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

ID: 70f57594-8866-538f-a8cc-8da0c609056b

STIX ID: report--70f57594-8866-538f-a8cc-8da0c609056b

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Pierluigi Paganini

...
...

F5 disclosed a critical NGINX vulnerability (CVE-2026-42533, CVSS 9.2) where specially crafted HTTP requests against regex-based map configurations can trigger a heap buffer overflow, leading to crashes and, in some circumstances (e.g., ASLR bypass), remote code execution; patches and workarounds have been released and researchers have published a static scanner while delaying PoC release to allow patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.