logo

F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution

ID: a298fd31-387a-5ac8-ab5e-0f89f3492a13

STIX ID: report--a298fd31-387a-5ac8-ab5e-0f89f3492a13

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Pierluigi Paganini

...
...

F5 released emergency patches for multiple critical NGINX vulnerabilities—notably CVE-2026-42530 (a Use-After-Free in ngx_http_v3_module when HTTP/3/QUIC is enabled) and CVE-2026-42055 (a heap-based buffer overflow affecting proxy/grpc modules under specific HTTP/2 proxy and header-validation-disabled configurations). Both carry CVSS scores of 9.2 and can cause worker crashes and potentially remote code execution in environments where ASLR is disabled or bypassed; updates for NGINX Open Source, NGINX Plus, and NGINX Gateway Fabric have been issued and no exploitation in the wild has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.