All news
web server security
(3 articles)June 3, 2026
HTTP/2 Bomb Vulnerability: DoS Risk on NGINX & Apache
A new HTTP/2 bomb vulnerability lets attackers remotely crash NGINX, Apache, IIS, Envoy, and Cloudflare. Here's what developers need to know and do now.
May 17, 2026
NGINX CVE-2026-42945: Worker Crashes and RCE Risk
NGINX CVE-2026-42945 is being actively exploited, crashing worker processes and potentially enabling RCE. Here's what developers need to patch now.
May 14, 2026
NGINX Rewrite Flaw Enables Unauthenticated RCE
An 18-year-old flaw in NGINX's rewrite module allows unauthenticated RCE. Learn what's affected, how the exploit works, and how to protect your servers.