Close Menu
    What's Hot

    Why were Waymo cars driving into active construction zones?

    Democratic Socialist Defeats Centrist in the D.C. Mayoral Primary

    Are prices really dropping in the US, as Trump claims? | Donald Trump News

    Facebook X (Twitter) Instagram
    Trending
    • Why were Waymo cars driving into active construction zones?
    • Democratic Socialist Defeats Centrist in the D.C. Mayoral Primary
    • Are prices really dropping in the US, as Trump claims? | Donald Trump News
    • The Iran War Will Leave the U.S. and Israel Weaker for Years to Come
    • Fallout From the Iran Deal
    • Valve is so behind on Steam Controller orders that some won’t ship until 2027
    • Will Bogotá Elect Its Own Bukele?
    • Three Medals of Honor to Be Awarded to Vietnam and Afghanistan Veterans
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

    adminBy adminJune 18, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 18, 2026Vulnerability / Cloud Security

    F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

    F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.

    The vulnerabilities are listed below –

    • CVE-2026-42530 (CVSS v4 score: 9.2) – A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
    • CVE-2026-42055 (CVSS v4 score: 9.2) – A heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules that could be triggered by a remote unauthenticated attacker when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 MB, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
    Cybersecurity

    Both shortcomings have been patched in the following versions –

    • CVE-2026-42530

      –

      • NGINX Open Source 1.31.0 – 1.31.1 (Fixed in 1.31.2)
      • NGINX Gateway Fabric 2.0.0 – 2.6.3 (Fixed in 2.6.4)
      • NGINX Gateway Fabric 1.3.0 – 1.6.2
      • NGINX Instance Manager 2.17.0 – 2.22.0
      • NGINX Ingress Controller 5.0.0 – 5.5.0
      • NGINX Ingress Controller 4.0.0 – 4.0.1
      • NGINX Ingress Controller 3.5.0 – 3.7.2
    • CVE-2026-42055

      –

      • NGINX Plus 37.0.0 – 37.0.1 (Fixed in 37.0.2.1)
      • NGINX Plus R33 – R36 (Fixed in R36 P6)
      • NGINX Open Source 1.31.1 (Fixed in 1.31.2)
      • NGINX Open Source 1.30.0 – 1.30.2 (Fixed in 1.30.3)
      • NGINX Instance Manager 2.17.0 – 2.22.0
      • F5 WAF for NGINX 5.9.0 – 5.13.1
      • NGINX App Protect WAF 5.2.0 – 5.8.0
      • NGINX App Protect WAF 4.10.0 – 4.16.0
      • F5 DoS for NGINX 4.9.0
      • NGINX App Protect DoS 4.3.0 – 4.7.0
      • NGINX Gateway Fabric 2.0.0 – 2.6.3 (Fixed in 2.6.4)
      • NGINX Gateway Fabric 1.3.0 – 1.6.2
      • NGINX Ingress Controller 5.0.0 – 5.5.0
      • NGINX Ingress Controller 4.0.0 – 4.0.1
      • NGINX Ingress Controller 3.5.0 – 3.7.2

    As mitigations, F5 has outlined the following actions –

    • CVE-2026-42530 – Disable HTTP/3
    • CVE-2026-42055 – Remove the ignore_invalid_headers off directive from the configuration, or reduce the large_client_header_buffers directive size below 2 MB

    Although F5 makes no mention of the vulnerabilities being exploited in the wild, security flaws in F5 products have been repeatedly exploited by bad actors.

    As recently as last month, another critical security defect in NGINX Plus and NGINX Open Source (CVE-2026-42945, CVSS score: 9.2), also called NGINX Rift, came under active exploitation within days after public disclosure.

    Code critical Enabling Execution Flaws Nginx Open Patches remote source
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleMeta CTO: Company morale is ‘probably one of the worst it’s ever been’ after layoffs
    Next Article 44 Best Father’s Day Gifts for Dads (2026)
    admin
    • Website

    Related Posts

    ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security

    June 18, 2026

    Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

    June 18, 2026

    How to Find Hidden Access Risks Inside Your Network

    June 18, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Why were Waymo cars driving into active construction zones?

    Democratic Socialist Defeats Centrist in the D.C. Mayoral Primary

    Are prices really dropping in the US, as Trump claims? | Donald Trump News

    The Iran War Will Leave the U.S. and Israel Weaker for Years to Come

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by