logo

Critical Code Execution Vulnerabilities in Oracle Linux nginx

ID: 73509fbb-0b6d-5c86-b3f1-1284371e0bbf

STIX ID: report--73509fbb-0b6d-5c86-b3f1-1284371e0bbf

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

Oracle Linux 8 and 9 are affected by critical nginx vulnerabilities (CVE-2026-42945 — arbitrary code execution; CVE-2026-9256 — denial of service) impacting nginx 1.20 and 1.24. Both flaws were disclosed in May 2026, proof-of-concept exploits appeared shortly after, and administrators are urged to apply patches immediately to protect service availability and system integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.