Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
2026-07-20T01:24:16Z•a61ba09ba00b4f916dcdd57c37a82842d5f678a3bf9ac0f512aedd701c67c1cd
ACR StealerCISAClickFixClickLockDaxinGoSerpentGoldenEyeDogMicrosoft SharePointNadMeshOpenSSLSandworm (UAC-0145)SonicWall SMAStupigTELEPUZViteVenomWordPressZero-daydenial of serviceheap buffer overflowmalwaren8n token exchange flawnginxnpmremote code executionsupply chain
What happened
Multiple high‑risk vulnerabilities and active campaigns were reported: a critical nginx heap‑buffer overflow (CVE-2026-42533) patched in nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 that can crash workers and may enable RCE; SonicWall SMA 1000 series zero‑days were actively exploited prior to disclosure; WordPress “wp2shell” core vulnerabilities now carry CVEs and enable unauthenticated code execution; OpenSSL “HollowByte” can induce DoS with 11‑byte TLS requests; and CISA added a critical SharePoint RCE (CVE-2026-58644, CVSS 9.8) to KEV. Multiple malware and supply‑chain campaigns are active:·
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a61ba09ba00b4f916dcdd57c37a82842d5f678a3bf9ac0f512aedd701c67c1cd
- Enrichment time
- 2026-07-20T01:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.