Back Gbhackers F5 Patches NGINX Vulnerability Enabling Code Execution and DoS Attacks
F5 has released an out-of-band security notification addressing multiple high‑severity vulnerabilities in NGINX components that can enable remote code execution (RCE) and denial‑of‑service (DoS) attacks in certain configurations, urging customers to patch or upgrade affected deployments immediately.
On June 17, 2026, F5 issued an out-of-band security notification (K000161614) summarizing several high- and medium-severity flaws across NGINX Open Source, NGINX Plus, NGINX Instance Manager, NGINX Gateway Fabric, NGINX Ingress Controller, and associated App Protect WAF/DoS modules.
The advisory, updated on June 18, 2026, highlights the elevated risk to HTTP/2, HTTP/3, and gRPC traffic handling paths and provides customers with a consolidated view of impacted products, versions, and fixed releases.
This notification supplements F5’s regular Quarterly Security Notifications and is being echoed by national CERTs, underscoring its urgency.
The most prominent issue, tracked as CVE-2026-42530 and detailed in F5 article K000161616, affects the NGINX ngx_http_v3_module when NGINX is configured to use the HTTP/3 QUIC module.
A remote, unauthenticated attacker can send specially crafted HTTP/3 traffic to reopen a QPACK encoder stream, triggering a use-after-free in the NGINX worker process that can repeatedly crash workers, causing DoS , and potentially allowing code execution on systems where ASLR is disabled or can be bypassed.
F5 assigns this bug a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 9.2, reflecting its high-to-critical impact profile on modern deployments.
A second high-severity issue, CVE-2026-42055 (K000161584), targets NGINX Plus and NGINX Open Source when using the ngx_http_proxy_v2_module or gRPC module with HTTP/2 backends.
When proxy_http_version is set to 2 or gRPC upstreams are enabled, malformed or malicious HTTP/2 or gRPC streams can lead to memory-handling flaws that may manifest as crashes and possibly code execution, depending on the environment’s hardening.
This flaw is also rated at 8.1 (CVSS v3.1) and 9.2 (CVSS v4.0), aligning it with the HTTP/3 vulnerability in terms of severity from F5’s perspective.
F5 additionally discloses multiple high-severity vulnerabilities in NGINX Gateway Fabric, including CVE-2026-11311 and CVE-2026-50107, described in K000161611 and K000161785, respectively.
These issues affect various 2.x Gateway Fabric releases. They can result in routing instability, service disruptions, or other impacts on integrity and availability within service-mesh and gateway deployments. F5 introduces fixes in Gateway Fabric 2.6.4, which is now the recommended target version for affected customers.
Below is a consolidated table of the high‑severity CVEs and their core technical metadata as provided by F5, focusing on CVSS scores, affected products, versions, and fixes.
F5 strongly recommends upgrading NGINX Open Source to 1.31.2, NGINX Plus to 37.0.2.1 or R36 P6, NGINX Gateway Fabric to 2.6.4, and aligning Ingress Controller and App Protect components with forthcoming patched releases as they become available.
Organizations unable to patch immediately should consider turning off HTTP/3 and QUIC support, restricting HTTP/2 and gRPC exposure, enforcing strict access controls, and hardening ASLR and other exploitation mitigations as interim measures.
Administrators are further advised to monitor F5’s quarterly security notifications and vendor RSS/email channels to track future updates and any changes in exploitation status.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s…
AWS has introduced “Continuum,” a new security capability designed to detect, validate, and remediate code…
A new security analysis has revealed that Microsoft SQL Server 2025’s native AI capabilities can…
Microsoft’s June 2026 cumulative update for Windows 11 (KB5095051, OS Build 28000.2269) introduces an unexpected…
Threat actors are actively exploiting a critical security flaw in the widely used Gravity SMTP…
Splunk has disclosed a critical security vulnerability in its AI Toolkit that could allow authenticated…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
