CVE-2026-27651 is a denial-of-service vulnerability in NGINX Plus and NGINX Open Source configurations using ngx_mail_auth_http_module. Undisclosed requests can terminate worker processes when CRAM-MD5 or APOP authentication is enabled and the authentication server permits retries by returning the Auth-Wait response header. The underlying implementation defect and triggering request details are not disclosed. Software versions beyond End of Technical Support were not evaluated.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible denial-of-service vulnerability in the NGINX mail authentication HTTP module can terminate worker processes under the specified authentication and retry conditions. The reported impact is high availability loss, with no confidentiality or integrity impact. The reference assigns CVSS v3 7.5 and CVSS v4 8.7. For the Echo packages covered by this plugin, update nginx and related packages to version 1.26.3-3+deb13u7+e1 or later. End-of-Technical-Support versions were not evaluated.
A vulnerability referenced by the TuxCare CentOS 7 CLSA-2026-1790172301 security update; the content provides no technical flaw description.
A network-reachable vulnerability with no required privileges or user interaction that affects availability, based on the supplied CVSS v4 vector. The notice indicates a patch was published.
An NGINX vulnerability that can cause denial of service through undisclosed requests when ngx_mail_auth_http_module is enabled. Red Hat advisory RHSA-2026:15966 includes a fix in updated nginx:1.26 packages for affected Red Hat Enterprise Linux 9.6 offerings.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.