Skip to content
Threat Feed

Vendor

Nginx

39 briefs RSS
low advisory

Detection of Unusual File Creation by Web Server Processes on Linux

This brief details a behavioral detection strategy for identifying potential web shell deployment and persistence mechanisms by monitoring anomalous file creation activities originating from common web server processes on Linux.

nginx +44 persistence web-shell linux behavioral-detection
1r 4t updated
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
low advisory

Web Server Local File Inclusion Activity

This brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.

Nginx +4 local-file-inclusion web-vulnerability information-disclosure remote-code-execution discovery
1r 4t 1i
high advisory

Unusual Child Process Execution by Web Servers on Linux

This detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.

Elastic Defend +45 persistence execution command-and-control initial-access linux webserver webshell privilege-escalation +4
2r 5t 13i updated
high advisory

Unusual Command Execution via Linux Web Server Processes

This brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.

Apache HTTP Server +40 linux-threat persistence web-exploitation webshell command-execution detection-rule elastic-security
1r 4t
medium advisory

Suspicious Command Execution via Linux Web Server

This brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.

Apache HTTP Server +45 webserver command-injection web-shell vulnerability-exploitation persistence linux
1r 14t
medium advisory

NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)

An injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.

NGINX Ingress Controller kubernetes vulnerability injection webserver cve
2t 1c
high advisory

CVE-2026-42533 Heap Buffer Overflow in NGINX Map Directive

A heap buffer overflow vulnerability, CVE-2026-42533, exists in NGINX Plus and NGINX Open Source when a 'map' directive uses regex matching and references its capture variables before the map's output variable or uses a non-cacheable variable under certain conditions, allowing an unauthenticated attacker to send crafted HTTP requests causing denial-of-service or remote code execution.

PoC NGINX Plus +9 vulnerability nginx webserver buffer-overflow DoS RCE
3t 2c updated
medium advisory

Web Server Cloud Metadata SSRF Exploitation

Attackers are actively exploiting Server-Side Request Forgery (SSRF) vulnerabilities in public-facing web applications to access cloud instance metadata services, such as those on AWS, GCP, and Azure, to harvest temporary credentials and sensitive instance details.

AWS +8 ssrf cloud-security web-exploitation credential-access initial-access webserver
1r 2t 7i
high advisory

CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability

An injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.

PoC NGINX Plus +10 config-injection nginx kubernetes cloud-native web-vulnerability cve
2r 1t 5c 2i updated
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
medium advisory

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.

Elastic Defend endpoint linux persistence initial-access vulnerability
3r 2t
low advisory

Unusual Command Execution from Web Server Parent Process on Linux

This rule detects potential command execution from a web server parent process on a Linux host, indicating a possible web shell attack where adversaries exploit web server vulnerabilities to execute arbitrary commands.

Elastic Defend +2 web-shell command-execution persistence linux
2r 3t
critical advisory

Nginx Vulnerability Leading to Remote Code Execution and Denial of Service

A vulnerability in Nginx allows a remote attacker to execute arbitrary code and cause a denial-of-service condition, affecting Nginx Open Source versions 1.x before 1.30.2, versions after 1.31.0 before 1.31.1, Nginx Plus versions 37.x before 37.0.1.1, and versions Rx before R36 P5 or R32 P7.

NGINX Open Source +1 nginx rce dos CVE-2026-9256 webserver
2r 2t
high threat

NGINX Open Source and NGINX Plus Vulnerability Allows Denial of Service and Potential Code Execution

A remote, anonymous attacker can exploit a vulnerability in NGINX Open Source and NGINX Plus to perform a denial-of-service attack and potentially execute arbitrary code.

NGINX Open Source +1 nginx denial-of-service code-execution
2r 1t
medium advisory

BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers

A commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.

Photoshop +3 iis malware maas seo fraud
2r 1t 6i
high advisory

NGINX JavaScript Heap Buffer Overflow Vulnerability (CVE-2026-8711)

NGINX JavaScript is vulnerable to a heap buffer overflow (CVE-2026-8711) when the js_fetch_proxy directive is configured with client-controlled variables and ngx.fetch(), allowing unauthenticated attackers to cause worker process restarts or, with ASLR disabled, code execution via crafted HTTP requests.

NGINX JavaScript cve heap-buffer-overflow nginx
2r 3t 1c
critical advisory

Multiple Vulnerabilities in NGINX Open Source and NGINX Plus

Multiple vulnerabilities in NGINX Open Source and NGINX Plus allow a remote, anonymous attacker to bypass security measures, execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.

nginx open source +1 nginx vulnerability webserver
2r 8t
high threat

CVE-2026-42945: NGINX ngx_http_rewrite_module Heap Buffer Overflow

NGINX Plus and NGINX Open Source are vulnerable to a heap buffer overflow (CVE-2026-42945) due to crafted HTTP requests when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed PCRE capture with a replacement string that includes a question mark, potentially leading to denial of service or code execution.

NGINX Plus +1 cve CVE-2026-42945 nginx heap overflow denial of service webserver
2r 3t 1c
medium advisory

nginx-ui Information Disclosure Vulnerability

A remote, authenticated attacker can exploit a vulnerability in nginx-ui to disclose sensitive information.

nginx-ui information-disclosure web-application
2r 1t
high advisory

SPIP RCE Vulnerability in Nginx Configurations (CVE-2026-8430)

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability exploitable in certain Nginx configurations, allowing attackers to execute arbitrary code within the web server's context.

SPIP +1 vulnerability rce webserver
2r 1t 1c
critical advisory

Nginx-UI Unauthenticated Remote Code Execution via Backup Restore

Nginx-UI is vulnerable to unauthenticated remote code execution (RCE) via the `POST /api/restore` endpoint, allowing attackers to inject arbitrary commands into the configuration.

nginx-ui rce authentication bypass command injection devops
2r 2t
medium advisory

Web Server Local File Inclusion Activity Detected

Detection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.

Nginx +4 web-server lfi file-inclusion discovery credential-access initial-access
3r 4t
high advisory

NGINX ngx_http_dav_module Buffer Overflow Vulnerability (CVE-2026-27654)

A buffer overflow vulnerability (CVE-2026-27654) exists in the ngx_http_dav_module of NGINX Open Source and NGINX Plus, potentially allowing attackers to terminate the NGINX worker process or modify files outside the document root by exploiting specific configurations with MOVE or COPY methods.

NGINX Open Source +1 nginx dav buffer-overflow cve-2026-27654 denial-of-service
2r 1t
low advisory

Potential HTTP Downgrade Attack Detected

The new_terms rule detects potential HTTP downgrade attacks by identifying HTTP traffic using a different HTTP version than typically used, potentially exposing systems to vulnerabilities in older protocols.

Nginx +3 defense-evasion http-downgrade web-server
2r 1t
low advisory

Web Server Error Response Spike Indicating Reconnaissance

An unusual spike in web server error codes (500, 502, 503, 504) may indicate reconnaissance activities like vulnerability scanning or fuzzing, where attackers probe for weaknesses, potentially leading to exploitation of server-side issues.

Nginx +4 web-server reconnaissance vulnerability-scanning fuzzing
2r 2t
high advisory

Web Shell Activity Detection via Process Monitoring

This brief focuses on detecting malicious activity related to web shells on Windows systems by identifying the execution of command interpreters and scripting engines as child processes of common web server processes, potentially indicating unauthorized command execution and persistent access.

Windows +3 webshell persistence initial-access execution
2r 4t
medium advisory

Web Server Potential Remote File Inclusion Activity

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.

Nginx +4 rfi webserver vulnerability
2r 2t
low advisory

Web Server Remote File Inclusion Activity Detected

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths to read sensitive files, gain system information, or further compromise the server.

Nginx +4 remote-file-inclusion web-server discovery
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
high advisory

Kubernetes Nginx Ingress LFI Attack

Detection of local file inclusion (LFI) attacks targeting Kubernetes Nginx ingress controllers through analysis of Kubernetes logs.

Nginx Ingress Controller kubernetes lfi nginx ingress cloud
2r 1t
low advisory

Web Server Potential Command Injection Request

The rule detects potential command injection attempts via web server requests by identifying URLs that contain suspicious patterns commonly associated with command execution payloads.

Nginx +4 web-server command-injection persistence
2r 5t
medium advisory

Web Server Request Command Injection Attempt

Detection of potential command injection attempts via web server requests by identifying URLs containing suspicious patterns associated with command execution payloads, which attackers exploit to execute arbitrary commands on the server.

Apache +4 command-injection web-server persistence
2r 5t
low advisory

Web Server Reconnaissance via Unusual User Agents

Detection of unusual spikes in web server requests with uncommon or suspicious user-agent strings indicative of reconnaissance attempts to identify web application vulnerabilities or brute-force attacks.

Nginx +4 web-server reconnaissance vulnerability-scanning user-agent
2r 4t
medium advisory

Kubernetes Nginx Ingress Remote File Inclusion Attempt

This analytic detects remote file inclusion (RFI) attacks targeting Kubernetes Nginx ingress controllers by analyzing Kubernetes logs from the Nginx ingress controller and identifying suspicious URL requests, potentially leading to arbitrary code execution or sensitive data access.

Nginx Ingress Controller +1 kubernetes nginx rfi remote file inclusion cloud
2r 1t
medium advisory

AzuraCast Account Takeover via X-Forwarded-Host Poisoning

AzuraCast is vulnerable to password reset poisoning due to unconditionally trusting the X-Forwarded-Host header, allowing an attacker to inject a malicious host into the password reset URL, exfiltrate the reset token, reset the victim's password, and disable 2FA, leading to account takeover.

azuracast +2 account takeover x-forwarded-host password reset poisoning
2r 3t 2i
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detected

Detection of web server discovery or fuzzing activity indicated by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, suggesting attempts to discover hidden resources.

Nginx +4 web-server fuzzing reconnaissance web-application
2r 2t
low advisory

Web Server Discovery or Fuzzing Activity

Detection of potential web server discovery or fuzzing activity characterized by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, indicating attackers are probing for hidden resources.

Nginx +4 reconnaissance web-server fuzzing
2r 2t