logo

F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks

ID: ff5fbc47-0dfa-558c-bebc-a04a97d2c331

STIX ID: report--ff5fbc47-0dfa-558c-bebc-a04a97d2c331

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Guru Baran

...
...

F5 disclosed three high-severity vulnerabilities in NGINX (including CVE-2026-42533 with CVSS v4.0 9.2) that affect NGINX Plus, NGINX Open Source, Ingress Controller, Gateway Fabric, App Protect WAF, and Instance Manager; flaws include a heap buffer overflow triggered by `map` regex captures, uninitialized memory exposure in the `slice` module, and a use‑after‑free in the `ssi` module. The advisory details affected versions, available patches/fixes, recommended mitigations (use named regex captures, patch promptly), and notes no impact to certain F5 products outside the NGINX data plane.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.