logo

Critical NGINX Vulnerability CVE-2026-42533 Poses RCE and DoS Risks

ID: 9ae70bdd-2ce9-55ca-8dbd-74b7931e2c8f

STIX ID: report--9ae70bdd-2ce9-55ca-8dbd-74b7931e2c8f

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

F5 disclosed CVE-2026-42533, a critical heap-buffer-overflow in NGINX's map directive that can be triggered by specially crafted HTTP requests to cause denial-of-service or remote code execution; the flaw affects both NGINX Plus and the open-source builds, a proof-of-concept appeared on July 4, 2026, and F5 published fixes on July 15, 2026 while urging immediate upgrades and configuration review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.