Connect With an Expert: 888-985-8971
Zultys Security Advisory Notice - SAN26-007 Rev 1.0
Vulnerability in NGINX (CVE-2026-42533)
Evaluated Products
MX-SE, MX-SE II, MX-E and MX-Virtual systems – Firmware versions 18.4.13 and 19.0.16.
Impacted Products
None
Affected Releases
Not applicable
Impacted 3rd Party Products
Not applicable
Introduction
On July 15, 2026 details of a vulnerability in NGINX, related to map directives using regex matching, was published in the CVE Vulnerability Database under CVE-2026-42533.
The vulnerability may allow an unauthenticated attacker to send requests that cause a heap buffer overflow leading to a denial-of-service (DoS).
Description
Zultys have evaluated the reported vulnerability and confirmed that MX-SE, MX-SE II, MX-E and MX-Virtual products running firmware versions 18.4.13 or 19.0.16 are not impacted.
Note: Earlier firmware versions which have reached end of support are not evaluated.
Contact
If additional information is required contact support@zultys.com or your Authorized Zultys Channel Partner.
