CVE Tools

F5 Patches Critical, High-Severity NGINX Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchNGINX PlusNGINX Open Source

Our summary

F5 has issued out-of-band updates to fix multiple NGINX vulnerabilities, including critical issues in HTTP modules tracked as CVE-2026-42530 and CVE-2026-42055. These flaws (CVSS 9.2) could be exploited without authentication to trigger memory corruption (use-after-free or heap-based buffer overflow), potentially leading to denial-of-service and, if ASLR is disabled or bypassable, arbitrary code execution. F5 also patched additional NGINX Gateway Fabric bugs CVE-2026-11311 and CVE-2026-50107 that may let authenticated attackers inject malicious configuration directives, plus other medium-severity NGINX issues affecting memory disclosure or stability.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store