CVE-2026-28755Disclosure(f5 / nginx_open_source)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch f5 nginx_open_source systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source
  • nginx_plus

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-03-26); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
nginx_open_sourcenginx_plus

4 versions affected across 2 products

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-03-24: 2Mentions · 2026-03-26: 4Mentions · 2026-03-27: 1Mentions · 2026-05-16: 1Mentions · 2026-05-20: 1Mentions · 2026-07-27: 1PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-26: 4Technical Details · 2026-03-24: 2Technical Details · 2026-03-27: 1Technical Details · 2026-05-20: 103-2403-2603-2705-1605-2007-27
Signal classification3 categories
Disclosure
550.0%
Patch
440.0%
General
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure2
2026-03-264
Patch4
2026-03-271
Disclosure1
2026-05-161
General1
2026-05-201
Disclosure1
2026-07-271
Disclosure1
Full discourse10 posts
  • mufeed vh@mufeedvh
    Disclosure

    Introducing ENDGINX - 5 CVEs in NGINX with open models. We let loose GLM 5.1 and 5.2 by @Zai_org on the NGINX codebase. The work resulted in six fixed vulnerabilities across five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533. First of our open-model vulnerability research series. https://winfunc.com/research/endginx

    Post summary

    The post announces five newly discovered CVEs in NGINX identified using open GLM models, highlighting that the vulnerabilities have been fixed in research.

    130192549.2K
    4.8K followersView on X
  • mufeed vh@mufeedvh
    General

    We're doing an experiment with open models @winfunction to see how far we can push them to find vulns in hardened targets. So far: - $4.5K in bounties from Chrome VRP with a few more pending, with the scans costing less than $100. - 2 CVEs in NGINX (CVE-2026-28755 & CVE-2026-42926). And watch out for the next release! - And 60ca500faea0fc70816bb9c53af3815e2af3e6c962b4b4ea63c33c62ebb4240d 👀 We're writing a blog on this soon.

    Post summary

    The post announces the discovery of two CVEs during an experiment and hints at a blog, but provides no technical details or actionable information.

    51321014713.1K
    4.8K followersView on X
  • winfunc@winfunction
    Disclosure

    New CVE in NGINX - CVE-2026-28755 NGINX stream module allows TLS handshake to succeed with revoked client certificates when ssl_ocsp on is configured. This vulnerability was autonomously discovered by Winfunc's AI agent. Read the write-up here: https://winfunc.com/findings/CVE-2026-28755

    Post summary

    A new CVE (CVE-2026-28755) has been discovered in NGINX, where the stream module permits TLS handshakes with revoked client certificates when ssl_ocsp is enabled. The write-up link suggests detailed findings are available.

    12091407
    2.3K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The Kusanagi NGinx module update 1.28.3‑1.el9 includes fixes for several CVE‑2026 vulnerabilities, but no PoC, exploit, or active exploitation details are mentioned.

    0202085
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    The announcement delivers a patch update for kusanagi-nginx128 that addresses several CVEs, with no evidence of PoC, exploit code, or active exploitation.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    The release updates Kusanagi modules to address several CVEs, providing patches but no PoC, exploit details, or evidence of active exploitation.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    The announcement details a Kusanagi module update that addresses six CVEs, providing a patch via a release link.

    01010100
    200 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28755 NGINX SSL Module Vulnerability Bypasses Certificate Revocation Checks https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28755

    Post summary

    The post announces a new NGINX SSL module flaw (CVE‑2026‑28755) that bypasses certificate revocation checks, but provides no PoC, exploit code, or patch information.

    0000140
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28755 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with th… https://www.cve.org/CVERecord?id=CVE-2026-28755

    Post summary

    The text announces CVE-2026-28755, noting a vulnerability in NGINX’s ngx_stream_ssl_module that mishandles revoked certificates, with no PoC, exploit, or patch information provided.

    0001096
    56.8K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-28755 | F5 NGINX Open Source/NGINX Plus ngx_stream_ssl_module authorization (K000160368 / Nessus ID 306672) https://ift.tt/otvN0Ux A vulnerability classified as critical has been found in F5 NGINX Open Source and NGINX Plus. This issue affects the function ngx_stream_…

    Post summary

    An announcement detailing a critical vulnerability (CVE-2026-28755) affecting F5 NGINX, with no PoC, exploit, or patch information provided.

    0000056
    974 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more