Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-serv...
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer overflow has existed for 18 years, affecting all versions from 0.6.27 to 1.30.0. Attacke...
F5 disclosed a critical vulnerability in NGINX, identified as CVE-2026-42533, which can lead to remote code execution (RCE) and denial-of-service (DoS) attacks. The flaw is a heap buffer overflow triggered by crafted HTTP requests that exploit unsafe regex processing in the map directive. This vulne...
On June 3, 2026, Ubuntu published a security advisory detailing multiple vulnerabilities in nginx affecting various Ubuntu LTS versions. Key issues include improper handling of memory operations in the ngx_mail_smtp_module (CVE-2025-53859), which could leak sensitive information, and flaws in the ng...