F5 NGINX out-of-band security updates (multiple vulnerabilities)
Security Patch Release
Summary
Hide ▲
Show ▼
F5 released out-of-band security updates for NGINX after finding multiple web server vulnerabilities, including two critical flaws that could enable remote code execution or denial of service on affected systems. The fixes cover NGINX Plus, NGINX Open Source, NGINX Gateway Fabric, and NGINX Instance Manager. Administrators unable to patch immediately have product-specific mitigations, but the release remains urgent because the flaws affect vulnerable non-default configurations.
Related Happenings
F5 security patch release for CVE-2026-42530
Security Patch Release
H score39
First: 18.06.2026 20:32
Last: 18.06.2026 20:32
Sources 1
About this happening:
F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
F5 security patch release for CVE-2026-42530
Security Patch ReleaseAbout this happening: F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
Nginx security patch release for CVE-2026-49975
Security Patch Release
H score42
First: 03.06.2026 22:08
Last: 03.06.2026 22:08
Sources 1
About this happening:
Vendors released fixes for the HTTP/2 Bomb DoS issue, closing a path that could let a single client exhaust server memory within seconds. The patch set covers nginx 1.29...
Nginx security patch release for CVE-2026-49975
Security Patch ReleaseAbout this happening: Vendors released fixes for the HTTP/2 Bomb DoS issue, closing a path that could let a single client exhaust server memory within seconds. The patch set covers nginx 1.29...
NGINX and Apache HTTPD HTTP/2 Bomb mitigations
Advisory/Mitigation
H score46
First: 03.06.2026 11:33
Last: 03.06.2026 11:33
Sources 1
About this happening:
Calif issued mitigation guidance for NGINX and Apache HTTPD operators after HTTP/2 Bomb was found to enable a remote denial-of-service against default HTTP/2 confi...
NGINX and Apache HTTPD HTTP/2 Bomb mitigations
Advisory/MitigationAbout this happening: Calif issued mitigation guidance for NGINX and Apache HTTPD operators after HTTP/2 Bomb was found to enable a remote denial-of-service against default HTTP/2 confi...
NGINX rewrite-rule workaround for CVE-2026-42945
Advisory/Mitigation
H score23
First: 14.05.2026 18:43
Last: 14.05.2026 18:43
Sources 1
About this happening:
F5 issued a workaround for vulnerable NGINX rewrite rules, reducing exposure to CVE-2026-42945 for operators who cannot upgrade immediately. The guidance replaces...
NGINX rewrite-rule workaround for CVE-2026-42945
Advisory/MitigationAbout this happening: F5 issued a workaround for vulnerable NGINX rewrite rules, reducing exposure to CVE-2026-42945 for operators who cannot upgrade immediately. The guidance replaces...
F5 security patch release for CVE-2026-42945
Security Patch Release
H score25
First: 14.05.2026 09:00
Last: 14.05.2026 09:00
Sources 1
About this happening:
F5 released security fixes for NGINX Plus and NGINX Open Source after disclosing multiple vulnerabilities, including CVE-2026-42945. The patch release covers i...
F5 security patch release for CVE-2026-42945
Security Patch ReleaseAbout this happening: F5 released security fixes for NGINX Plus and NGINX Open Source after disclosing multiple vulnerabilities, including CVE-2026-42945. The patch release covers i...
Latest development: 17.05.2026 14:57
VulnCheck reported active exploitation of CVE-2026-42945 against NGINX Plus and NGINX Open, saying honeypot networks saw weaponized crafted HTTP requests that can crash worker processes and, when ASLR is disabled, enable remote code execution.
Timeline
-
18.06.2026 14:33 2 articles · 27d ago
F5 releases out-of-band patches for critical NGINX vulnerabilities
Mitigation Patch UpdateF5 released out-of-band security updates for NGINX to address CVE-2026-42530 and CVE-2026-42055, two critical flaws in ngx_http_v3_module and ngx_http_proxy_v2_module/ngx_http_grpc_module that unauthenticated remote attackers could abuse on non-default configurations for denial of service or code execution. F5 also fixed CVE-2026-11311 and CVE-2026-50107 in NGINX Gateway Fabric, which allow authenticated attackers to inject arbitrary NGINX configuration directives, and provided temporary mitigations such as disabling HTTP/3 or adjusting header-related directives for environments that cannot patch immediately.
Show sources
- F5 issues out-of-band patches for critical NGINX vulnerabilities — www.bleepingcomputer.com — 18.06.2026 14:33
- F5 issues out-of-band patches for critical NGINX vulnerabilities — www.bleepingcomputer.com — 18.06.2026 14:33