CVE-2026-8711Disclosure(f5 / njs)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch f5 njs systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

5.8/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • njs

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 29 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 23 signals
  • Disclosure: 15 classified signals
  • General: 6 classified signals
  • Peaked 7d ago at 8 mentions (2026-05-20); latest day: 1
  • 29 total mentions across 9 days

Affected systems

Vendors
Products
njs

Deep dive

Activity timeline29 mentions / 9d
02468Mentions · 2026-05-19: 2Mentions · 2026-05-20: 8Mentions · 2026-05-21: 8Mentions · 2026-05-22: 1Mentions · 2026-05-27: 2Mentions · 2026-05-30: 1Mentions · 2026-06-07: 5Mentions · 2026-07-06: 1Mentions · 2026-08-31: 1PoC Mentioned / Linked · 2026-05-20: 1Active Exploitation · 2026-06-07: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 5Technical Details · 2026-05-21: 6Technical Details · 2026-05-22: 1Technical Details · 2026-05-27: 2Technical Details · 2026-05-30: 1Technical Details · 2026-06-07: 5Technical Details · 2026-07-06: 105-1905-2005-2105-2205-2705-3006-0707-0608-31
Signal classification5 categories
Disclosure
1551.7%
Patch
620.7%
General
620.7%
False Positive
13.4%
Active Exploitation
13.4%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure1Patch1
2026-05-208
Disclosure5General2Patch1
2026-05-218
Disclosure4False Positive1General1Patch2
2026-05-221
General1
2026-05-272
Disclosure1General1
2026-05-301
Patch1
2026-06-075
Active Exploitation1Disclosure4
2026-07-061
Patch1
2026-08-311
General1
Full discourse20 posts
  • Hamid Kashfi@hkashfi
    Disclosure

    I've not even unpacked my bag from the trip and two new separate RCEs for Nginx are presented. So now we have 3 RCEs, in the world's most deployed web-server, in the span of few weeks. Nginx-Rifle, Nginx-PoolSlip Nginx-??? (likely CVE-2026-8711, which would make it Nginx-njs I guess?)

    Post summary

    The post announces three newly discovered RCE vulnerabilities in Nginx, including a possible CVE‑2026‑8711, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    41521456825.1K
    10.5K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs). Unauthenticated attackers can trigger heap overflows and potential RCE. #NGINX #CyberSecurity #InfoSec #VulnerabilityAlert #CVE20268711 #SysAdmin #WebSecurity #DevOps https://securityonline.info/nginx-javascript-njs-module-heap-overflow-vulnerability-cve-2026-8711/ https://t.co/2ksjKMAlVb

    Post summary

    F5 warns of a critical heap overflow vulnerability (CVE‑2026‑8711) in NGINX JavaScript (njs) that could let unauthenticated attackers achieve remote code execution.

    1602141.2K
    12.5K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Nueva vulnerabilidad de NGINX en JavaScript (njs) permite ejecutar código malicioso remotamente Se ha detectado una nueva vulnerabilidad en NGINX JavaScript (njs) , identificada como CVE-2026-8711 https://blog.elhacker.net/2026/05/nueva-vulnerabilidad-de-nginx-en.html

    Post summary

    The text announces a new NGINX njs vulnerability (CVE-2026-8711) that permits remote code execution, with additional details likely in the linked blog.

    0501461.8K
    141.0K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة جديدة في NGINX تسمح للمهاجمين عن بعد بتنفيذ شفرة خبيثة تم اكتشاف ثغرة جديدة في NGINX JavaScript (njs) تحمل الرقم CVE-2026-8711، تسمح للمهاجمين عن بعد غير المصادقين بتحفيز تجاوز سعة المخزن المؤقت القائم على الكومة، مما قد يؤدي إلى رفض الخدمة وفي بعض الحالات، تنفيذ الشفرة عن بعد في عملية عامل NGINX. يعود سبب الضعف إلى كيفية تعامل توجيه js_fetch_proxy مع المتغيرات التي يتحكم بها العميل عند دمجها مع عملية ngx.fetch(). يُنصح بـ تحديث الإصدارات المتضررة وتطبيق التصحيحات الأمنية اللازمة. 🔗 للمزيد: https://cybersecuritynews.com/?p=150432

    Post summary

    A new remote code execution flaw (CVE‑2026‑8711) in NGINX JavaScript (njs) is announced, with emphasis on applying patches and updates to mitigate the heap‑overflow risk.

    00040364
    299 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    Son 24 saatte olanlar: - ArchLinux tarafında yeni LPE güvenlik açığı - Nginx tarafında iki yeni açık - Nginx-PoolSlip ve CVE-2026-8711 (Nginx-njs) - Drupal güvenlik açıkları - First VPN Service (1VPNS) Kolluk Kuvvetleri Operasyonu - GitHub Hack olayı, internal depoların satışı

    Post summary

    A short announcement of several newly identified vulnerabilities across different platforms, without specific technical or remediation details.

    00040480
    1.2K followersView on X
  • rooten@r00teen
    General

    1/ lagi iseng googling nginx, eh malah nemuin berita ada 2 CVE critical baru 😅 CVE-2026-42945 (NGINX Rift) & CVE-2026-8711 keduanya CVSS 9.2 — alias critical langsung cek server production 🧵

    Post summary

    The tweet announces two new critical NGINX CVEs (CVSS 9.2) but provides only basic detail and no information on exploitation or mitigation.

    20020102
    1.3K followersView on X
  • Cyber Edition@CyberEdition
    Disclosure

    Read More: https://thecyberedition.com/cve-2026-8711-nginx-javascript-flaw-allows-rce-on-servers/ https://t.co/Z6Li5X6kwf

    Post summary

    The link references a disclosure article about CVE‑2026‑8711, a JavaScript flaw in NGINX that enables remote code execution, but no further details on exploitation or mitigation are provided.

    0103065
    739 followersView on X
  • VulnTracker@vuln_tracker
    General

    @hkashfi 3 RCEs in the world's most deployed web server. In a few weeks. Nginx-Rift. Nginx-Rifle. Nginx-PoolSlip. And a 4th (CVE-2026-8711) possibly still being named. At this point NGINX isn't having a bad month. It's having a bad identity crisis. http://vulntracker.io

    Post summary

    The tweet lists several RCEs in NGINX and hints at a forthcoming CVE, but it provides no PoC, exploit tool, patch, or evidence of active exploitation.

    00012500
    655 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 #CVE-2026-8711 in NGINX #JavaScript (njs): Critical Heap Overflow Opens Door to Remote Code Execution -Fact Checker: ✅: 3 ❌: 0 || 3/3 http://undercodenews.com/cve-2026-8711-in-nginx-javascript-njs-critical-heap-overflow-opens-door-to-remote-code-execution/

    Post summary

    The tweet announces CVE-2026-8711 as a critical heap overflow in NGINX's JavaScript (njs) that could lead to remote code execution, referencing a news article for details.

    1001092
    861 followersView on X
  • Windows Forum@windowsforum
    Patch

    🪟 Windows folks hear “CVE” and panic, but this one is basically: only njs 0.9.4-0.9.8 + js_import + js_fetch_proxy + client-controlled vars + ngx.fetch. Patch if you’re actually doing the thing. https://windowsforum.com/threads/cve-2026-8711-nginx-njs-triage-on-windows-when-to-patch-and-when-out-of-scope.435046/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #WindowsSecurity #Cve20268711 #NginxNjs #ReverseProxy https://t.co/lfEoZOr486

    Post summary

    The post is a practical triage advisory for CVE‑2026‑8711, outlining the affected Nginx‑njs components and urging users to patch only if they are using those features.

    0001053
    1.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    03:17 UTC: Thread live on @lyrie_ai. 0day Intel: F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs).

    Post summary

    F5 has announced a critical CVSS 9.2 vulnerability (CVE-2026-8711) affecting NGINX's JavaScript engine 'njs', with no PoC, exploit, or patch details provided.

    1000047
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:03 UTC: First exploit attempt in the wild. 0day Intel: F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs).

    Post summary

    A first exploit attempt for CVE-2026-8711 is reported, with F5 warning of a critical flaw in NGINX NJS, but no PoC, exploit code, or patch details are provided.

    1000056
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    03:06 UTC: Lyrie Sentinel flagged it. 0day Intel: F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs).

    Post summary

    F5 has publicly announced CVE-2026-8711 as a critical flaw with a 9.2 CVSS score affecting NGINX JavaScript (njs); no PoC, exploit, or patch details are supplied.

    1000047
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    03:14 UTC: GPT-5 enrichment complete. 65 words. 1 citations. 0day Intel: F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs).

    Post summary

    F5 warns of a critical CVE-2026-8711 flaw in NGINX's njs module (CVSS 9.2), but provides no PoC, exploit code, active exploitation evidence, or patch information.

    1000047
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    03:03 UTC: CVE-2026-8711 disclosed. F5 warns of a critical 9.2 CVSS flaw (CVE-2026-8711) in NGINX JavaScript (njs). Unauthenticated attackers can trigger he

    Post summary

    F5 has disclosed CVE‑2026‑8711, a critical flaw in NGINX JavaScript (njs) with a 9.2 CVSS score, noting that unauthenticated attackers can trigger it, but no further exploitation or mitigation details are provided.

    1000053
    253 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-8711 (CVSS 8.1) - NGINX JavaScript heap buffer overflow via js_fetch_proxy directive. Unauthenticated remote exploitation possible. Code execution on systems w/o ASLR. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/8Ge5MVH42A

    Post summary

    This tweet announces the high‑severity CVE‑2026‑8711, a heap buffer overflow in NGINX, and urges readers to apply the patch immediately, while providing key technical details.

    0100097
    32 followersView on X
  • rooten@r00teen
    False Positive

    4/ oke langsung cek server nginx -V 2>&1 | grep -i njs output kosong ✅ — njs gak keinstall, CVE-2026-8711 skip

    Post summary

    The user indicates that CVE-2026-8711 is not applicable because the nginx njs module is not present on the server, effectively treating the vulnerability as a false positive for this environment.

    1000018
    771 followersView on X
  • rooten@r00teen
    Patch

    3/ CVE-2026-8711 ini khusus buat yang pakai modul njs (NGINX JavaScript) heap buffer overflow via js_fetch_proxy + variabel dari client ($http_, $arg_, dll) affect njs 0.9.4 – 0.9.8 fix-nya: upgrade ke njs 0.9.9

    Post summary

    CVE-2026-8711 is a heap buffer overflow in the NGINX JavaScript (njs) module affecting versions 0.9.4–0.9.8; upgrading to njs 0.9.9 resolves the vulnerability.

    1000021
    771 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting F5 NGINX JavaScript (CVE-2026-8711) https://vuldb.com/vuln/364689

    Post summary

    The tweet announces that the severity of CVE-2026-8711 has been raised, but provides no technical details, PoC, or exploitation evidence.

    00001111
    2.2K followersView on X
  • Hannah Genie@hm_tech_travel
    Patch

    @The_Cyber_News If youre running js_fetch_proxy with client controlled variables, patch now. Dnt sleep on CVE-2026-8711, its unauthenticated and nasty.

    Post summary

    The tweet warns about CVE-2026-8711 as an unauthenticated, nasty flaw and urges users to apply patches, but provides no technical details or exploitation evidence.

    00010707
    77 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appf5njs---

Explore more