logo

F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

ID: d98304ed-1d49-5af2-ac42-f80d8899da94

STIX ID: report--d98304ed-1d49-5af2-ac42-f80d8899da94

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

...
...

F5 released emergency patches on June 17, 2026, for two critical NGINX vulnerabilities—CVE-2026-42530 (HTTP/3 use-after-free) and CVE-2026-42055 (HTTP/2 and gRPC heap buffer overflow)—both rated CVSS v4.0 9.2. The flaws allow unauthenticated remote code execution and DoS, potentially affecting a large portion of the web (NGINX runs on ~38% of active sites); immediate patching is advised and interim mitigations are suggested for systems that cannot be updated right away.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.