CVE-2026-27654 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
May 8, 2026
Last Seen
July 20, 2026

CVE-2026-27654 is a vulnerability tracked by ThreatCluster, appearing in 5 threat clusters built from 8 intelligence report mentions.

CVE-2026-27654 is a vulnerability tracked across 5 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed May 8, 2026; most recent activity July 20, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Security Advisories — nginx.org · July 20, 2026
  • Oracle Linux 9 NGINX Critical Arbitrary Code Execution Vuln ELSA-2026 — Linuxsecurity · June 25, 2026
  • Oracle Linux 9 nginx Critical Code Exec Denial of Service ELSA-2026 — Linuxsecurity · June 25, 2026
  • Oracle Linux 8 nginx Important Code Execution Vuln ELSA-2026 — Linuxsecurity · June 25, 2026
  • Ubuntu 20.04 LTS nginx Security Advisory for Critical DoS Vulnerabilities — Linuxsecurity · June 3, 2026
  • USN-8375-1: nginx vulnerabilities — Ubuntu · June 3, 2026
  • openSUSE Leap 15.6 nginx Major Vulnerabilities Buffer Overflows 2026-1761 — Linuxsecurity · May 8, 2026
  • SUSE nginx Important Memory Overread Buffer Overflow Vuln 2026-1761 — Linuxsecurity · May 8, 2026

Frequently asked questions

What is CVE-2026-27654?

CVE-2026-27654 is a vulnerability tracked by ThreatCluster, appearing in 5 threat clusters built from 8 intelligence report mentions.

Is CVE-2026-27654 still active?

The most recent intelligence report mentioning CVE-2026-27654 on ThreatCluster is dated July 20, 2026. Activity was first observed May 8, 2026, giving a tracked span from then to July 20, 2026.

What is CVE-2026-27654 associated with?

Across ThreatCluster reporting, CVE-2026-27654 most frequently co-occurs with DDoS, Denial of Service, Man-in-the-Middle, Zero-day Exploit, Ubuntu, among 12 tracked related entities.

What are the latest developments involving CVE-2026-27654?

The most significant recent cluster is “F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution” (24 articles · Updated June 18, 2026). CVE-2026-27654 appears across 5 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2026-27654?

CVE-2026-27654 appears in 8 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown