logo

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

ID: c3ed06ae-9d12-5822-ade0-99b67f26f8e8

STIX ID: report--c3ed06ae-9d12-5822-ade0-99b67f26f8e8

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

**CVE-2026-42533 — Critical pre-auth nginx RCE:** A two-pass PCRE capture-state bug in nginx allows attackers to trigger a heap overflow and leak heap pointers (defeating ASLR) via configurations combining regex map variables and regex captures, enabling reliable unauthenticated remote code execution; affected open-source nginx versions include 0.9.6–1.30.3 (stable) and 1.31.2 (mainline) and several NGINX Plus releases. Researchers achieved consistent exploitation in testing and advise immediate upgrade to nginx 1.30.4 / 1.31.3 or the corresponding patched NGINX Plus releases and auditing of vulnerable configuration patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.