Bleepingcomputer
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-service (DoS) attacks. CVE-2026-42530 is a use-after-free vulnerability in the HTTP/3 module, while CVE-2026-42055 is a heap buffer overflow in the HTTP/2 and gRPC modules. Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating their critical severity. F5 advises immediate patching, as exploitation could occur rapidly. The vulnerabilities impact a significant portion of the web, with NGINX running on approximately 38% of active websites worldwide. Patches are available for affected versions, and interim mitigations are suggested for those unable to update immediately.
Key Points: • F5 released critical patches for two NGINX vulnerabilities on June 17, 2026. • CVE-2026-42530 and CVE-2026-42055 allow remote code execution and DoS attacks. • Both vulnerabilities have a CVSS v4.0 score of 9.2, indicating critical severity.