Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-serv...
F5 disclosed a critical vulnerability in NGINX, identified as CVE-2026-42533, which can lead to remote code execution (RCE) and denial-of-service (DoS) attacks. The flaw is a heap buffer overflow triggered by crafted HTTP requests that exploit unsafe regex processing in the map directive. This vulne...
Recent updates for openSUSE NGINX address multiple vulnerabilities, including CVE-2026-42055, a heap-based buffer overflow affecting the ngx_http_proxy_v2_module and ngx_http_grpc_module, and CVE-2026-48142, a heap buffer over-read in the ngx_http_charset_module. Additionally, CVE-2026-40460 allows...