📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d
Vulnerabilities

CVE-2026-32647

High
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting
CWE-125 — Weakness Type
Published: Mar 24, 2026  ·  Modified: Mar 30, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

🤖 AI Executive Summary

CVE-2026-32647 is a buffer over-read/over-write vulnerability in NGINX's ngx_http_mp4_module affecting NGINX Plus R32-R34 and Open Source versions. An attacker can exploit this via specially crafted MP4 files to cause worker process termination or potentially achieve code execution. This vulnerability poses significant risk to organizations using NGINX as a reverse proxy or media server, particularly in Saudi Arabia's critical infrastructure sectors.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 28, 2026 16:16
🇸🇦 Saudi Arabia Impact Assessment
High impact on Saudi banking sector (SAMA-regulated institutions using NGINX for API gateways and load balancing), government digital services (NCA-supervised platforms), telecommunications infrastructure (STC, Mobily), and energy sector (ARAMCO subsidiaries). Media streaming services and CDN providers in Saudi Arabia are at elevated risk. Healthcare sector organizations using NGINX for telemedicine platforms are also vulnerable. The lack of available patches increases exposure window significantly.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Media and Broadcasting E-commerce and Retail Education
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all NGINX instances running ngx_http_mp4_module by checking configuration files for 'mp4' directive
2. Disable MP4 module processing immediately: comment out or remove 'mp4;' directive from nginx.conf
3. Implement network-level controls to block MP4 file uploads/processing until patching is available
4. Monitor NGINX worker process crashes and core dumps for exploitation attempts

COMPENSATING CONTROLS:
5. Deploy WAF rules to reject requests with MP4 content-type or .mp4 file extensions
6. Implement strict input validation on file upload endpoints
7. Use SELinux/AppArmor to restrict NGINX worker process capabilities
8. Enable NGINX access logging with detailed request inspection

DETECTION:
9. Monitor for: sudden NGINX worker process exits, abnormal memory access patterns, requests containing MP4 files
10. Alert on: POST/PUT requests with 'ftyp' magic bytes (MP4 signature), worker process segmentation faults
11. Implement IDS signatures for malformed MP4 atom structures

PATCHING STRATEGY:
12. Subscribe to F5 security advisories for patch availability
13. Prepare test environment for patch deployment immediately upon release
14. Establish rollback procedures before applying patches to production
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع مثيلات NGINX التي تقوم بتشغيل ngx_http_mp4_module بفحص ملفات الإعدادات عن توجيه 'mp4'
2. تعطيل معالجة وحدة MP4 فوراً: تعليق أو إزالة توجيه 'mp4;' من nginx.conf
3. تطبيق عناصر تحكم على مستوى الشبكة لحظر تحميل/معالجة ملفات MP4 حتى يتم إصدار التصحيحات
4. مراقبة أعطال عمليات عامل NGINX وملفات core dump لمحاولات الاستغلال

عناصر التحكم التعويضية:
5. نشر قواعد WAF لرفض الطلبات ذات نوع محتوى MP4 أو امتدادات ملفات .mp4
6. تطبيق التحقق الصارم من صحة الإدخال على نقاط تحميل الملفات
7. استخدام SELinux/AppArmor لتقييد قدرات عملية عامل NGINX
8. تفعيل تسجيل وصول NGINX مع فحص الطلبات التفصيلي

الكشف:
9. مراقبة: خروج مفاجئ لعمليات عامل NGINX، أنماط وصول الذاكرة غير الطبيعية، الطلبات التي تحتوي على ملفات MP4
10. التنبيه على: طلبات POST/PUT تحتوي على بايتات سحرية 'ftyp' (توقيع MP4)، أعطال تجزئة عملية العامل
11. تطبيق توقيعات IDS لهياكل ذرات MP4 المشوهة

استراتيجية التصحيح:
12. الاشتراك في تنبيهات أمان F5 لتوفر التصحيحات
13. تحضير بيئة اختبار لنشر التصحيحات فوراً عند إصدارها
14. إنشاء إجراءات التراجع قبل تطبيق التصحيحات على الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.3.1 - Configuration management
🔵 SAMA CSF
SAMA CSF ID.RA-1 - Asset Management and Vulnerability Management SAMA CSF PR.IP-12 - Security patch and update management SAMA CSF DE.CM-8 - Malicious code detection
🟡 ISO 27001:2022
ISO 27001:2022 A.12.3.1 - Configuration management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 6.3.1 - Vulnerability scanning
📦 Affected Products / CPE 18 entries
f5:nginx_plus:r32
f5:nginx_plus:r32
f5:nginx_plus:r32
f5:nginx_plus:r32
f5:nginx_plus:r33
f5:nginx_plus:r33
f5:nginx_plus:r33
f5:nginx_plus:r33
f5:nginx_plus:r34
f5:nginx_plus:r34
f5:nginx_plus:r34
f5:nginx_plus:r35
f5:nginx_plus:r35
f5:nginx_plus:r36
f5:nginx_plus:r36
f5:nginx_plus:r36
f5:nginx_open_source
f5:nginx_open_source
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-125
Exploit No
Patch ✗ No
Published 2026-03-24
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-125
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.