Skip to content

CVE-2026-32647

CVE

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
March 25, 2026
Last Seen
August 27, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-serv...

F5 disclosed a critical vulnerability in NGINX, identified as CVE-2026-42533, which can lead to remote code execution (RCE) and denial-of-service (DoS) attacks. The flaw is a heap buffer overflow triggered by crafted HTTP requests that exploit unsafe regex processing in the map directive. This vulne...

Oracle Linux versions 8 and 9 have been found vulnerable to multiple critical code execution and denial of service vulnerabilities in nginx. The vulnerabilities include CVE-2026-42945, which allows arbitrary code execution, and CVE-2026-9256, which enables denial of service through specially crafted...

On June 3, 2026, Ubuntu published a security advisory detailing multiple vulnerabilities in nginx affecting various Ubuntu LTS versions. Key issues include improper handling of memory operations in the ngx_mail_smtp_module (CVE-2025-53859), which could leak sensitive information, and flaws in the ng...

Public Exploits

Checking GitHub for proof-of-concept code…