LIVE · cybersecurity feed
Live wire

denial of service

CVE-2026-42533critical

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

A critical vulnerability (CVE-2026-42533) has been discovered in NGINX, potentially allowing remote attackers to crash worker processes or even execute arbitrary code. The flaw, present in versions from 0.9.6 up to 1.31.2, arises from a specific configuration involving regex-based maps and string expressions. While F5 has released patches, researchers suggest that existing mitigations might not be entirely effective, emphasizing the need for immediate upgrades.