Critical NGINX Vulnerability CVE-2026-42533 Poses RCE and DoS Risks
ID: 9ae70bdd-2ce9-55ca-8dbd-74b7931e2c8f
STIX ID: report--9ae70bdd-2ce9-55ca-8dbd-74b7931e2c8f
Feed Name: ThreatCluster
Threat Score
F5 disclosed CVE-2026-42533, a critical heap-buffer-overflow in NGINX's map directive that can be triggered by specially crafted HTTP requests to cause denial-of-service or remote code execution; the flaw affects both NGINX Plus and the open-source builds, a proof-of-concept appeared on July 4, 2026, and F5 published fixes on July 15, 2026 while urging immediate upgrades and configuration review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
