F5 Out-of-Band Security Alert: Multiple Vulnerabilities Unveiled in NGINX Plus and Open Source
ID: 01253192-d8b4-5a8d-bf03-76450bb8bf61
STIX ID: report--01253192-d8b4-5a8d-bf03-76450bb8bf61
Feed Name: securityonline.info
F5 released an out-of-band advisory (2026-03-24) detailing multiple critical and high-severity vulnerabilities in NGINX Plus and NGINX Open Source — including a DAV module buffer overflow (CVE-2026-27654, CVSS 8.8), MP4 module over-read/over-write issues (CVE-2026-27784, CVE-2026-32647, CVSS ~8.5), and a mail auth crash/DoS (CVE-2026-27651, CVSS 8.7). The flaws can cause worker termination, file-name modification outside document roots, and in some cases may lead to code execution; fixes are provided across NGINX Plus and Open Source branches and administrators are urged to update to the listed patched versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
