SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-60065

LOW · CVSS 3.7 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

NGINX Plus instances utilizing the MQTT filter module are vulnerable to a heap buffer over-read, which can be exploited by unauthenticated attackers to restart the NGINX worker process. While the impact is limited to the data plane, organizations relying on NGINX for handling MQTT traffic should prioritize patching to mitigate potential disruptions. This vulnerability is particularly relevant for those still using supported versions of NGINX Plus.

CVE
CVE-2026-60065
Severity
LOW
CVSS
3.7
EPSS
0.27%
Nginx

Original NVD Description

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Related CVEs

Other vulnerabilities affecting the same vendor(s)