Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > nginx
#nginx

Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution

20 July 2026  |  dark6  |  Vulnerability

A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...

>> read more

HTTP/2 Bomb: Single-Attacker Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

8 June 2026  |  dark6  |  Vulnerability

A newly disclosed exploit called the 'HTTP/2 Bomb' can exhaust tens of gigabytes of server memory in seconds using just a home internet connection. Five of the world's...

>> read more

CVE-2026-9256 “nginx-poolslip”: Critical NGINX Flaw Enables Unauthenticated DoS and Code Execution

25 May 2026  |  dark6  |  Vulnerability

A critical heap buffer overflow in the NGINX rewrite module (CVE-2026-9256, "nginx-poolslip") allows unauthenticated remote attackers to crash NGINX workers or execute code. Proof-of-concept activity is already circulating...

>> read more

Hackers Actively Exploiting Critical NGINX RCE Vulnerability in the Wild

19 May 2026  |  dark6  |  Vulnerability

Hackers are actively exploiting CVE-2026-42945, a critical heap buffer overflow in NGINX Open Source and NGINX Plus, with real-world attacks confirmed just days after public disclosure. With approximately...

>> read more

Critical CVE-2026-33032 (MCPwn): Actively Exploited nginx-ui Flaw Enables Full Web Server Takeover in Two HTTP Requests

21 April 2026  |  dark6  |  Vulnerability

CVE-2026-33032 (MCPwn) is a CVSS 9.8 authentication bypass in nginx-ui being actively exploited in the wild. Attackers can seize full control of Nginx web servers in two HTTP...

>> read more