Cybersecuritynews F5 NGINX Plus & Open Source Vulnerability Allows Code Execution via MP4 Files
Article Content
- •CVE-2026-32647 allows code execution via crafted MP4 files in NGINX deployments.
- •The vulnerability affects both NGINX Plus and NGINX Open Source with a CVSS v4.0 score of 8.5.
- •Immediate action is recommended for systems using the MP4 streaming module.
F5 has disclosed a high-severity vulnerability, tracked as CVE-2026-32647, affecting both NGINX Plus and NGINX Open Source. This flaw allows attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by exploiting crafted MP4 files. The vulnerability specifically impacts deployments where the MP4 streaming module is enabled in the server configuration. The CVSS v4.0 base score for this vulnerability is 8.5, indicating a significant risk. Affected systems include any NGINX installations with the MP4 module active. Security teams are advised to review their configurations and apply necessary mitigations. The vulnerability was published on March 24, 2026, and is currently under scrutiny for potential exploits.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track F5 and CVE-2026-32647 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Nginx Vulnerabilities Affect Oracle Linux Versions Recent advisories detail multiple vulnerabilities in Nginx across Oracle Linux versions 8, 9, and 10, including CVE-2026-60005 and CVE-2026-56434, which could lead to memory disclosure and denial of service. These vulnerabilities are particularly concerning as they allow for remote denial of service attacks via…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…