NLnet Labs patched a critical heap overflow in the DNSSEC validator of Unbound, one of the most widely used recursive DNS resolvers. Tracked as CVE-2026-81642, the flaw can be triggered when a resolver queries a zone an attacker controls, and it can lead to remote code execution. The bug lies in how the validator parses a signing-key record whose owner name points back into the record's own data. Every Unbound release up to and including 1.26.0 is affected, and the fix is in 1.26.1, which also addresses eight other flaws, including a second that could allow code execution. No exploitation is reported, but resolvers query attacker-controlled zones during normal operation.
F5 patched a critical nginx vulnerability that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 sits in nginx's script engine, the code that builds strings from configuration directives at request time, and only surfaces under a specific configuration: a regex based map whose output is referenced in a string expression after an earlier regex capture. Under that pattern the engine's two pass evaluation disagrees on buffer size. Triggering it crashes or restarts the worker, and F5 says code execution may be possible where address randomization is disabled or bypassed. Fixes shipped July 15.
An AI-discovered bug hidden in NGINX since 2008 lets anyone on the internet crash NGINX worker processes or, with ASLR disabled, run code on the server using a single crafted HTTP request. The flaw, named NGINX Rift (CVE-2026-42945, CVSS 9.2), sits in the rewrite module that powers URL rewriting in almost every NGINX deployment. It triggers when a config uses a rewrite directive with unnamed regex captures and a question mark, followed by another rewrite, if, or set directive - a common pattern in API gateway setups. NGINX runs roughly a third of the websites on the public internet.