logo

F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

ID: 402603df-dffb-57e6-8ccf-856d5e4c56b7

STIX ID: report--402603df-dffb-57e6-8ccf-856d5e4c56b7

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-22

...
...

On June 17, 2026, F5 released emergency patches for two critical NGINX vulnerabilities—CVE-2026-42530 (use-after-free in HTTP/3) and CVE-2026-42055 (heap buffer overflow in HTTP/2 and gRPC)—which allow unauthenticated remote code execution and DoS; both are assigned CVSS v4.0 scores of 9.2, impact a large portion of the web (NGINX runs on ~38% of active sites), and immediate patching or interim mitigations are strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.