SECURITYTHE HACKER NEWS
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 addressed a critical NGINX vulnerability (CVE-2026-42533) that allows remote, unauthenticated attackers to crash worker processes or potentially execute code via crafted HTTP requests. Fixes were released on July 15 in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1.
Related Signal
Adjacent reporting
- 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
- No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out