<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nginx on it-learn.io | IT, Networking &amp; Cybersecurity Blog</title><link>https://blog.it-learn.io/tags/nginx/</link><description>Recent content in Nginx on it-learn.io | IT, Networking &amp; Cybersecurity Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 18 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.it-learn.io/tags/nginx/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-42945 NGINX Heap Overflow Exploited — MiniPlasma Windows Zero-Day and 7-Eleven Breach</title><link>https://blog.it-learn.io/posts/2026-05-18-cve-2026-42945-nginx-heap-overflow-exploited-miniplasma-wind/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://blog.it-learn.io/posts/2026-05-18-cve-2026-42945-nginx-heap-overflow-exploited-miniplasma-wind/</guid><description>Active exploitation of CVE-2026-42945 in NGINX, a weaponized Windows kernel zero-day with no patch, 7-Eleven&amp;rsquo;s confirmed breach by ShinyHunters, and npm supply chain attacks using the Shai-Hulud framework.</description></item><item><title>Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited — Exchange XSS, NGINX RCE, and Shai-Hulud Worm Goes Public</title><link>https://blog.it-learn.io/posts/2026-05-15-cisco-sd-wan-zero-day-cve-2026-20182-exploited-exchange-xss/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://blog.it-learn.io/posts/2026-05-15-cisco-sd-wan-zero-day-cve-2026-20182-exploited-exchange-xss/</guid><description>Three actively exploited zero-days — Cisco SD-WAN authentication bypass (CVSS 10), Microsoft Exchange XSS-to-code-exec, and an npm supply chain worm that hit OpenAI — plus an 18-year-old NGINX RCE and TeamPCP open-sourcing their attack framework.</description></item><item><title>PAN-OS Critical RCE CVE-2026-0300 — CVSS 9.8 Buffer Overflow Plus NGINX 18-Year Flaw and G7 AI SBOM Guidance</title><link>https://blog.it-learn.io/posts/2026-05-14-pan-os-critical-rce-cve-2026-0300-cvss-9-8-buffer-overflow-p/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://blog.it-learn.io/posts/2026-05-14-pan-os-critical-rce-cve-2026-0300-cvss-9-8-buffer-overflow-p/</guid><description>Palo Alto drops four PAN-OS RCEs including a CVSS 9.8 unauthenticated buffer overflow in User-ID. An 18-year-old NGINX heap overflow surfaces at CVSS 9.2. G7 publishes first coordinated AI SBOM guidance. MuddyWater and FamousSparrow expand targeting across manufacturing and energy.</description></item></channel></rss>