VORANT. Threat Intelligence Sign in Get the full feed

Critical remote code execution and denial of service vulnerability (CVE-2026-9256)…

critical vulnerability

Critical remote code execution and denial of service vulnerability (CVE-2026-9256) affecting multiple versions of NGINX Open Source and NGINX Plus requires immediate patching.

A critical vulnerability has been identified in NGINX web server software that enables remote attackers to execute arbitrary code and cause denial of service conditions. The flaw affects NGINX Open Source versions 1.x prior to 1.30.2, versions after 1.31.0 but before 1.31.1, as well as NGINX Plus versions 37.x prior to 37.0.1.1 and Rx versions prior to R36 P5 or R32 P7. The vendor has explicitly stated that version 0.x of NGINX Open Source will not receive security patches for this issue.

Given NGINX's widespread deployment as a web server, reverse proxy, and load balancer across internet-facing infrastructure, this vulnerability presents significant risk to organizations running affected versions. The combination of remote code execution and denial of service capabilities makes this a high-priority patching target. Organizations should immediately consult F5's security bulletin K000161377 and apply available patches to mitigate exposure.

Mentioned in this report

Vulnerabilities CVE-2026-9256

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0643

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free