vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerability affects a wide range of NGINX versions dating back to 2011, and while initial reports focused on… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt