Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

2026-07-20T01:24:16Za61ba09ba00b4f916dcdd57c37a82842d5f678a3bf9ac0f512aedd701c67c1cd
ACR StealerCISAClickFixClickLockDaxinGoSerpentGoldenEyeDogMicrosoft SharePointNadMeshOpenSSLSandworm (UAC-0145)SonicWall SMAStupigTELEPUZViteVenomWordPressZero-daydenial of serviceheap buffer overflowmalwaren8n token exchange flawnginxnpmremote code executionsupply chain

What happened

Multiple high‑risk vulnerabilities and active campaigns were reported: a critical nginx heap‑buffer overflow (CVE-2026-42533) patched in nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 that can crash workers and may enable RCE; SonicWall SMA 1000 series zero‑days were actively exploited prior to disclosure; WordPress “wp2shell” core vulnerabilities now carry CVEs and enable unauthenticated code execution; OpenSSL “HollowByte” can induce DoS with 11‑byte TLS requests; and CISA added a critical SharePoint RCE (CVE-2026-58644, CVSS 9.8) to KEV. Multiple malware and supply‑chain campaigns are active:·

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a61ba09ba00b4f916dcdd57c37a82842d5f678a3bf9ac0f512aedd701c67c1cd
Enrichment time
2026-07-20T01:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.