F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution

First seen 18 Jun 2026, 12:57 UTC BleepingcomputerCybersecuritynewsGbhackersSecurityaffairs.CoFeeds.4Sysops+16 90% similarity 80.0

Article Content

Browse articles
ThreatCluster

On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-service (DoS) attacks. CVE-2026-42530 is a use-after-free vulnerability in the HTTP/3 module, while CVE-2026-42055 is a heap buffer overflow in the HTTP/2 and gRPC modules. Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating their critical severity. F5 advises immediate patching, as exploitation could occur rapidly. The vulnerabilities impact a significant portion of the web, with NGINX running on approximately 38% of active websites worldwide. Patches are available for affected versions, and interim mitigations are suggested for those unable to update immediately.

Key Points: • F5 released critical patches for two NGINX vulnerabilities on June 17, 2026. • CVE-2026-42530 and CVE-2026-42055 allow remote code execution and DoS attacks. • Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating critical severity.

ThreatCluster AI How this analysis works

Timeline

2009-09-15
CVE-2009-2629 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-09
CVE-2009-3555 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-24
CVE-2009-3896 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2009-11-24
CVE-2009-3898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-01-13
CVE-2009-4487 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-06-14
CVE-2010-2266 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2010-06-14
CVE-2010-2263 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2011-12-08
CVE-2011-4315 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2012-04-17
CVE-2012-1180 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2012-04-17
CVE-2012-2089 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →