Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2900 articles · 109738 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE
f5 · nginx, nginx plus

Multiple Vulnerabilities in NGINX and NGINX Plus Allow Denial of Service, Data Manipulation, Security Bypass, and Potential Arbitrary Code Execution

72% confidence

Description

Multiple vulnerabilities in NGINX and NGINX Plus can be exploited by an attacker to perform denial of service attacks, manipulate data, bypass security measures, and potentially execute arbitrary code.

Affected Products

VendorProductVersions
f5nginx, nginx plus—

Related News (1 articles)

Tier B
BSI Advisories2d ago
[UPDATE] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedApr 8, 2026
Last enriched2d ago
Tags
denial of servicecode executionsecurity bypassdata manipulation
Trending Score19
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMPRE-CVE
Denial of Service Vulnerability in NGINX
Trending: 23
HIGHCVE-2026-27651
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP au
Trending: 10
HIGHCVE-2026-27784
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its term
Trending: 10
HIGHCVE-2026-32647
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting
Trending: 10
HIGHCVE-2026-27654
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may re
Trending: 10

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
Apr 8, 2026
Discovered by ZDM
Apr 8, 2026