Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities BSI Germany

[NEU] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen

Multiple vulnerabilities in NGINX and NGINX Plus (CVSS Base Score 8.1) allow a remote attacker to manipulate data, execute arbitrary code, disclose sensitive information, or cause a denial-of-service state. Affected versions include NGINX Open Source prior to 1.31.2 and 1.30.3, NGINX Plus prior to R36 P6 and 37.0.2.1, and NGINX Gateway Fabric prior to 2.6.4. A mitigation is available, though the specific patch versions or workaround details are not provided in the advisory.
Read Full Article →

[WID-SEC-2026-1995] NGINX und NGINX Plus: Mehrere Schwachstellen CVSS Base Score 8.1 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 17.06.2026 Stand 18.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung NGINX ist eine Webserver-, Reverse Proxy- und E-Mail-Proxy Software. NGINX Plus ist die kommerzielle Variante von NGINX, einer Webserver-, Reverse Proxy- und E-Mail Proxy Software. Produkte 17.06.2026 NGINX NGINX Open Source <1.31.2 NGINX NGINX Instance Manager NGINX NGINX Gateway Fabric <2.6.4 NGINX NGINX Ingress Controller NGINX NGINX Plus <37.0.2.1 NGINX NGINX Plus <R36 P6 NGINX NGINX Open Source <1.30.3 NGINX NGINX App Protect WAF NGINX NGINX App Protect DoS Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in NGINX und NGINX NGINX Plus ausnutzen, um Daten zu manipulieren, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article