Red Hat released Important security updates for nginx on RHEL 8 and RHEL 10 to fix two memory-safety vulnerabilities, CVE-2026-56434 and CVE-2026-60005. The flaws can lead to memory disclosure, denial of service, and, in the case of the heap buffer over-read tracked as CVE-2026-56434, possible memory modification. CVE-2026-60005 affects ngx_http_slice_module. Red Hat shipped updated packages including nginx 1.24.0-3.module+el8.10.0+24644+2676a8ce.4 for RHEL 8 and nginx 1.26.3-6.el10_2.6 for RHEL 10 across major architectures such as x86_64, aarch64, ppc64le, and s390x.
Downstream distributions quickly mirrored the fixes: AlmaLinux 8 and Rocky Linux 8 published notices tied to the same Red Hat advisory stream, and Tenable plugin coverage shows both advisories map to CVE-2026-56434 and CVE-2026-60005, with no known public exploits reported. The vulnerability metadata also links the issues to common weakness classes including CWE-125 and CWE-824, the latter describing access of an uninitialized pointer, a defect type that can contribute to crashes, unintended memory access, and potential code execution in memory-unsafe software.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-25, Red Hat published Important advisory RHSA-2026:59496 for affected nginx:1.26 packages on Red Hat Enterprise Linux 9. The update addresses CVE-2026-56434 and CVE-2026-60005.
On 2026-08-25, Red Hat published Important advisory RHSA-2026:59362 for nginx on Red Hat Enterprise Linux 9. The update remediates CVE-2026-56434 and CVE-2026-60005 in affected nginx packages.
On 2026-08-25, Red Hat published Important advisory RHSA-2026:59490 for nginx 1.24 packages on Red Hat Enterprise Linux 9 and RHEL EUS 9.8. The update addresses CVE-2026-56434 and CVE-2026-60005.
A Tenable plugin for Rocky Linux 8 states that the patch publication date for the nginx notice tied to RLSA-2026:59216 was 2026-08-25. The notice covers nginx packages affected by CVE-2026-56434 and CVE-2026-60005.
On 2026-08-24, Red Hat published RHSA-2026:59220, an Important nginx security advisory for Red Hat Enterprise Linux 10. The update released nginx 1.26.3-6.el10_2.6 packages for multiple architectures to address CVE-2026-56434 and CVE-2026-60005.
On 2026-08-24, Red Hat published RHSA-2026:59216, an Important security advisory for the nginx:1.24 module on Red Hat Enterprise Linux 8. The update released nginx 1.24.0-3.module+el8.10.0+24644+2676a8ce.4 packages to fix CVE-2026-56434 and CVE-2026-60005.
Tenable plugin metadata states that the nginx vulnerabilities CVE-2026-56434 and CVE-2026-60005 had a vulnerability publication date of 2026-07-15. The advisories tie these issues to heap buffer over-read and memory disclosure/denial-of-service conditions.
Red Hat described CVE-2026-60005 as an ngx_http_slice_module flaw triggered by unauthenticated requests when the slice directive uses unnamed regex captures or during a background cache update. The issue can disclose limited memory or restart an NGINX worker; it affects the data plane only and requires the non-default module to be compiled with --with-http_slice_module.
Red Hat described CVE-2026-56434 as an ngx_http_ssi_module heap buffer over-read requiring SSI, proxy_pass, and proxy_buffering off, plus an attacker able to man-in-the-middle and control upstream responses. The issue can cause limited memory modification or an NGINX worker restart and affects the data plane rather than the control plane.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.