Wire · technology
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code ...
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
A 15-year-old pre-authentication remote code execution vulnerability in NGINX (CVE-2026-42533) allows attackers to crash workers and execute arbitrary code via a missing save/restore of regex capture state in the script engine. The flaw affects at least 13 call sites across multiple modules and is exploitable with high reliability using heap overflow and information leak primitives.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Cloud Infrastructure.
◆ ◆ The Wire takeaway
If you run NGINX in production anywhere, your edge is now compromised until you patch to 1.30.4 or later — no authentication needed, one GET request to leak ASLR, then RCE on the next hit. Patch this week before someone else finds it.
◆ Coverage
1 source · 20 Jul 2026
◆ Related on Wire
◆ Topics