logo

New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers

ID: 7e578a5b-c6ae-5880-8cc0-501c83fd8ab6

STIX ID: report--7e578a5b-c6ae-5880-8cc0-501c83fd8ab6

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Divya

...
...

A newly disclosed zero-day dubbed **nginx-poolslip** affects NGINX 1.31.0, enabling unauthenticated remote code execution and bypassing ASLR; it potentially exposes millions of servers, has no patch or CVE yet, and NebSec is coordinating responsible disclosure while urging administrators to apply mitigations (WAF rules, ASLR checks, interface restrictions) until an official fix is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.