Thursday , October 8 2026
nginx-poolslip

“nginx-poolslip” NGINX 0-Day Affects Millions of NGINX Servers To RCE

A security flaw dubbed nginx-poolslip has been revealed in NGINX version 1.31.0, the newest stable version of the most used web server software. The discovery, made by security researcher Vega of the NebSec security team, was announced via X (formerly Twitter) on May 21, 2026, sending shockwaves through the global security community.

FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws CVSS 10

The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws  CVSS 10

Contract and server dispute brought down Bangladesh’s digital payment

Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
Contract and server dispute brought down Bangladesh’s digital payment

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Just weeks ago, managers all over the world rushed to fix CVE-2026-42945. This is a serious flaw in NGINX’s ngx_http_rewrite_module with a CVSS v4 score of 9.2.

The flaw put about 5.7 million internet-facing NGINX servers at risk of denial-of-service attacks and conditional RCE. F5 fixed it in NGINX Open Source versions 1.31.0 and 1.30.1, which is the version that nginx-poolslip is aiming for.

New NGINX 0-Day “nginx-poolslip”

nginx-poolslip takes advantage of a mistake in how NGINX manages its memory. This lets attackers who are not logged in run code from a distance and might take over the whole system.

This flaw allows users to get around Address Space Layout Randomization (ASLR), which is a basic memory protection in the operating system meant to stop this type of memory corruption.

The attack surface traces back to an nginx-rift predecessor vulnerability, which affected earlier NGINX versions and was subsequently patched. NebSec’s research shows that the fix for nginx-rift did not solve the main memory pool issue. This means that nginx-poolslip could still appear in the new code.

NGINX runs around 30–40% of all web servers in the world. It is used for busy websites, reverse proxies, load balancers, and API gateways. nginx-poolslip only affects version 1.31.0, so admins quickly deployed the patch. After CVE-2026-42945, organizations that were careful might now face a new, unpatched risk.

CSN says there is no CVE ID given, and there is no official fix from F5/NGINX yet. NebSec will keep the full technical details secret for 30 days. This includes how to bypass ASLR until an official fix comes out.

Mitigations

Until an official patch is released, administrators should take the following interim measures:

Monitor NebSec and F5 security advisories closely for patch availability
Restrict public exposure of NGINX admin interfaces and deploy WAF rules to reduce the attack surface
Ensure ASLR is enforced system-wide by setting /proc/sys/kernel/randomize_va_space to 2Audit NGINX configurations for rewrite, if, and set directives using unnamed PCRE capture groups — a known precondition for pool-level memory corruption
Evaluate memory-safe alternatives such as Cloudflare Pingora for mission-critical infrastructure

Organizations are strongly advised to sign up for F5’s security updates and get ready for emergency patching as a quick fix is expected soon.

Check Also

CPanel

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These …