CVE-2026-32647 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
March 25, 2026
Last Seen
July 20, 2026

CVE-2026-32647 is a vulnerability tracked by ThreatCluster, appearing in 5 threat clusters built from 8 intelligence report mentions.

CVE-2026-32647 is a vulnerability tracked across 5 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed March 25, 2026; most recent activity July 20, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Security Advisories — nginx.org · July 20, 2026
  • Oracle Linux 9 NGINX Critical Arbitrary Code Execution Vuln ELSA-2026 — Linuxsecurity · June 25, 2026
  • Oracle Linux 9 nginx Critical Code Exec Denial of Service ELSA-2026 — Linuxsecurity · June 25, 2026
  • Oracle Linux 8 nginx Important Code Execution Vuln ELSA-2026 — Linuxsecurity · June 25, 2026
  • Ubuntu 20.04 LTS nginx Security Advisory for Critical DoS Vulnerabilities — Linuxsecurity · June 3, 2026
  • USN-8375-1: nginx vulnerabilities — Ubuntu · June 3, 2026
  • F5 NGINX Plus and Open Source Vulnerability Allow Attackers to Execute Code Using MP4 file — Cybersecuritynews · March 25, 2026
  • F5 NGINX Plus & Open‑Source Flaw Lets Attackers Execute Code via MP4 File — Gbhackers · March 25, 2026

Frequently asked questions

What is CVE-2026-32647?

CVE-2026-32647 is a vulnerability tracked by ThreatCluster, appearing in 5 threat clusters built from 8 intelligence report mentions.

Is CVE-2026-32647 still active?

The most recent intelligence report mentioning CVE-2026-32647 on ThreatCluster is dated July 20, 2026. Activity was first observed March 25, 2026, giving a tracked span from then to July 20, 2026.

What is CVE-2026-32647 associated with?

Across ThreatCluster reporting, CVE-2026-32647 most frequently co-occurs with DDoS, Denial of Service, Man-in-the-Middle, Zero-day Exploit, F5, among 12 tracked related entities.

What are the latest developments involving CVE-2026-32647?

The most significant recent cluster is “F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution” (24 articles · Updated June 18, 2026). CVE-2026-32647 appears across 5 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2026-32647?

CVE-2026-32647 appears in 8 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown