logo

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

ID: 878d9ece-2681-50cf-bb16-0306c1d825d5

STIX ID: report--878d9ece-2681-50cf-bb16-0306c1d825d5

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

...
...

F5 published patches for two critical NGINX Open Source vulnerabilities — most notably CVE-2026-42530, a CVSS 9.2 use-after-free in the HTTP/3 (ngx_http_v3_module) that enables unauthenticated remote code execution when HTTP/3 is enabled; administrators are urged to apply the June 18, 2026 patches immediately, disable HTTP/3 or block UDP/443 as temporary mitigations, and monitor for exploitation given NGINX's broad global use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.