Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
The Hacker News 19.07.2026 20:42
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Triggering it can crash or restart the worker, causing a denial of
Microsoft verteilt außerplanmäßiges Windows-Update
Heise Security 19.07.2026 08:09
Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.
„wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API
Heise Security 18.07.2026 05:19
Durch Verkettung einer SQL-Injection- und einer API-Lücke können Angreifer Code einschleusen. WordPress hat ein Update veröffentlicht, die Finder einen Hotfix.