15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution
RedSide Security July 20, 2026 CVE 41 views
A newly disclosed NGINX vulnerability, CVE-2026-42533, has reportedly been exploitable since 2011 and allows unauthenticated attackers to achieve remote code execution through a flaw in the NGINX script engine. The bug affects both NGINX Open Source and NGINX Plus and has now been patched in versions 1.30.4 and 1.31.3.