Nebula Security[verified]@nebusecurityDisclosure
A new RCE (CVE-2026-42530) in Nginx has been disclosed, with a patch already released and an upcoming technical writeup detailing an ASLR bypass.
Clandestine[verified]@akaclandestineDisclosure
The tweet announces a newly identified CVE-2026-42530 that grants remote code execution in NGINX, linking to additional details.
Zhenpeng (Leo) Lin[verified]@Markak_PoC
The post announces the open‑source release of an RCE proof‑of‑concept for CVE‑2026‑42533, detailing info‑leak and OOB heap write primitives that bypass ASLR, but makes no claim of active exploitation or a patch.
SOCRadar®[verified]@socradarPatch
F5 released out‑of‑band patches for two NGINX CVEs that enable remote DoS and possible RCE; administrators are urged to update immediately.
Zhenpeng (Leo) Lin[verified]@Markak_PoC
The post provides a GitHub link to a proof‑of‑concept exploit for an RCE and references F5 advisories for CVE‑2026‑42533 and CVE‑2026‑42530 without indicating active exploitation or patches.
dbugs[verified]@ptdbugsDisclosure
The article discloses technical details of CVE-2026-42530, a high‑severity use‑after‑free in NGINX’s HTTP/3 implementation, outlining its root cause and potential for arbitrary code execution.
Nicolas Krassas[verified]@DinosnDisclosure
The notice announces a new use‑after‑free vulnerability in nginx HTTP/3's QPACK encoder (CVE‑2026‑42530) and provides a link for further details, but offers no PoC, exploit, or mitigation information.
Trail of Bits[verified]@trailofbitsDisclosure
CVE‑2026‑42530 is a remote, unauthenticated nginx vulnerability that can crash the server and potentially allow code execution through HTTP/3, discovered after automated analysis by Evan Hellman using Codex.