ZDI-26-712: NoMachine nxhtd SSRF Information Disclosure Vulnerability
Executive Summary
A server‑side request forgery (SSRF) flaw in NoMachine’s nxhtd component allows unauthenticated attackers to trigger arbitrary outbound requests, potentially exposing sensitive data. The vulnerability, identified as CVE‑2026‑92210, carries a CVSS score of 7.2 and was disclosed by the Zero Day Initiative.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-16T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.
"We are Divine enough to ask and we are important enough to receive."
— Wayne Dyer