logo

F5 Out-of-Band Security Alert: Multiple Vulnerabilities Unveiled in NGINX Plus and Open Source

ID: 01253192-d8b4-5a8d-bf03-76450bb8bf61

STIX ID: report--01253192-d8b4-5a8d-bf03-76450bb8bf61

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

F5 released an out-of-band advisory (2026-03-24) detailing multiple critical and high-severity vulnerabilities in NGINX Plus and NGINX Open Source — including a DAV module buffer overflow (CVE-2026-27654, CVSS 8.8), MP4 module over-read/over-write issues (CVE-2026-27784, CVE-2026-32647, CVSS ~8.5), and a mail auth crash/DoS (CVE-2026-27651, CVSS 8.7). The flaws can cause worker termination, file-name modification outside document roots, and in some cases may lead to code execution; fixes are provided across NGINX Plus and Open Source branches and administrators are urged to update to the listed patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.