F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
ID: d98304ed-1d49-5af2-ac42-f80d8899da94
STIX ID: report--d98304ed-1d49-5af2-ac42-f80d8899da94
Feed Name: ThreatCluster
Threat Score
F5 released emergency patches on June 17, 2026, for two critical NGINX vulnerabilities—CVE-2026-42530 (HTTP/3 use-after-free) and CVE-2026-42055 (HTTP/2 and gRPC heap buffer overflow)—both rated CVSS v4.0 9.2. The flaws allow unauthenticated remote code execution and DoS, potentially affecting a large portion of the web (NGINX runs on ~38% of active sites); immediate patching is advised and interim mitigations are suggested for systems that cannot be updated right away.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
