logo

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

ID: 47da98b6-f5ed-5fbb-9eca-abb73ee316b2

STIX ID: report--47da98b6-f5ed-5fbb-9eca-abb73ee316b2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: [email protected] (The Hacker News)

...
...

F5 released updates addressing two critical NGINX vulnerabilities (CVE-2026-42530 and CVE-2026-42055) that may allow remote unauthenticated code execution under certain configurations; the advisory lists affected NGINX/Open Source, NGINX Plus, and multiple F5/NGINX product versions, provides fixed release versions, and recommends mitigations (disable HTTP/3 for CVE-2026-42530; remove ignore_invalid_headers off or reduce large_client_header_buffers for CVE-2026-42055). F5 reports no confirmed exploitation in the wild, but notes prior rapid exploitation of a similar NGINX defect.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.