Skip to content
F5 NGINX Plus & Open Source Vulnerability Allows Code Execution via MP4 Files

F5 NGINX Plus & Open Source Vulnerability Allows Code Execution via MP4 Files

First seen 25 Mar 2026, 21:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 26, 2026 at 21:17 UTC
  • CVE-2026-32647 allows code execution via crafted MP4 files in NGINX deployments.
  • The vulnerability affects both NGINX Plus and NGINX Open Source with a CVSS v4.0 score of 8.5.
  • Immediate action is recommended for systems using the MP4 streaming module.

F5 has disclosed a high-severity vulnerability, tracked as CVE-2026-32647, affecting both NGINX Plus and NGINX Open Source. This flaw allows attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by exploiting crafted MP4 files. The vulnerability specifically impacts deployments where the MP4 streaming module is enabled in the server configuration. The CVSS v4.0 base score for this vulnerability is 8.5, indicating a significant risk. Affected systems include any NGINX installations with the MP4 module active. Security teams are advised to review their configurations and apply necessary mitigations. The vulnerability was published on March 24, 2026, and is currently under scrutiny for potential exploits.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 169d ago How this analysis works

Timeline

2026-03-24
CVE-2026-32647 published
2026-03-25
F5 discloses high-severity vulnerability in NGINX

More articles in this cluster (2)

Following this threat?

Track F5 and CVE-2026-32647 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed