Bleepingcomputer F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
Article Content
- •F5 released critical patches for two NGINX vulnerabilities on June 17, 2026.
- •CVE-2026-42530 and CVE-2026-42055 allow remote code execution and DoS attacks.
- •Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating critical severity.
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-service (DoS) attacks. CVE-2026-42530 is a use-after-free vulnerability in the HTTP/3 module, while CVE-2026-42055 is a heap buffer overflow in the HTTP/2 and gRPC modules. Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating their critical severity. F5 advises immediate patching, as exploitation could occur rapidly. The vulnerabilities impact a significant portion of the web, with NGINX running on approximately 38% of active websites worldwide. Patches are available for affected versions, and interim mitigations are suggested for those unable to update immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (27)
Following this threat?
Track F5 and CVE-2009-2629 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…