15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx 1.30.4 (stable) and 1.31.3 (mainline), along with corresponding patches for NGINX Plus […]

The post 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: