Critical 9.2
CVE-2026-42533
NGINX Heap Buffer Overflow Vulnerability and PoC Release
Vendor / product: NGINX
Event date: 2026-07-25
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (3)
- CVE-2026–42533: The 15-Year-Old NGINX Bug That Became a Critical RCE medium.com · 2026-07-29
- Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code cybersecuritynews.com · 2026-07-28
- NGINX Heap Overflow Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code gbhackers.com · 2026-07-29
References
See CVE-2026-42533 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →