chiprook
← Security
SecurityOctober 10, 2026, 12:20

Nginx UI RCE flaw CVE-2026-107806 rated 9.4 Critical

A critical flaw, CVE-2026-107806 (CVSSv4 9.4), was found in the 0xJacky nginx-ui web console: an authenticated admin can achieve remote code execution by uploading a forged configuration backup. Versions 2.3.8 through below 2.5.0 are affected; the fix ships in 2.5.0.

Nginx UI RCE flaw CVE-2026-107806 rated 9.4 Critical
#Nginx-ui#Nginx
Read next
Security

CVE-2026-75937: unauthenticated root RCE in Digi routers scored 9.4

Security

Cisco patches critical NX-API RCE CVE-2026-76471 in NX-OS

Security

CVE-2026-75650: critical RCE in Adobe Commerce and Magento exploited in the wild

Security

CVE-2026-94545: RCE in Next.js via next/og and Satori