Skip to content
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

First seen 18 Jun 2026, 12:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 12:27 UTC

On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-service (DoS) attacks. CVE-2026-42530 is a use-after-free vulnerability in the HTTP/3 module, while CVE-2026-42055 is a heap buffer overflow in the HTTP/2 and gRPC modules. Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating their critical severity. F5 advises immediate patching, as exploitation could occur rapidly. The vulnerabilities impact a significant portion of the web, with NGINX running on approximately 38% of active websites worldwide. Patches are available for affected versions, and interim mitigations are suggested for those unable to update immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2009-09-15
CVE-2009-2629 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-09
CVE-2009-3555 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-24
CVE-2009-3896 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-24
CVE-2009-3898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-01-13
CVE-2009-4487 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-06-14
CVE-2010-2266 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-06-14
CVE-2010-2263 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2011-12-08
CVE-2011-4315 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2012-04-17
CVE-2012-1180 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2012-04-17
CVE-2012-2089 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (27)

Following this threat?

Track F5 and CVE-2009-2629 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed