Find notable cyber news and cases, enriched with sources, timelines, and signals.

F5 nginx security patch release for CVE-2026-42533

Security Patch Release
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

F5 shipped security fixes for nginx and NGINX Plus to close CVE-2026-42533, a critical heap buffer overflow. Operators on nginx 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 are on the patched path; earlier builds need an upgrade. The release removes a remote unauthenticated request path that can crash the worker process and, in some configurations, may allow remote code execution.

Related Happenings

F5 security patch release for CVE-2026-42530

Security Patch Release
H score39 First: 18.06.2026 20:32 Last: 18.06.2026 20:32 Sources 1

About this happening: F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...

F5 NGINX out-of-band security updates (multiple vulnerabilities)

Security Patch Release
H score34 First: 18.06.2026 14:33 Last: 18.06.2026 14:33 Sources 1

About this happening: F5 released out-of-band security updates for NGINX after finding multiple web server vulnerabilities, including two critical flaws that could enable remote code...

LiteLLM endpoint-hardening patch release (CVE-2026-42271)

Security Patch Release
H score59 First: 09.06.2026 09:26 Last: 09.06.2026 09:26 Sources 1

About this happening: BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN*...

Nginx security patch release for CVE-2026-49975

Security Patch Release
H score42 First: 03.06.2026 22:08 Last: 03.06.2026 22:08 Sources 1

About this happening: Vendors released fixes for the HTTP/2 Bomb DoS issue, closing a path that could let a single client exhaust server memory within seconds. The patch set covers nginx 1.29...

Redis security patch release for CVE-2026-23479

Security Patch Release
H score24 First: 03.06.2026 16:47 Last: 03.06.2026 16:47 Sources 1

About this happening: Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...

Timeline

  1. 19.07.2026 23:42 2 articles · 19h ago

    F5 nginx security patch release for CVE-2026-42533

    Initial Disclosure

    F5 shipped patched nginx and NGINX Plus builds for CVE-2026-42533 and told operators on earlier versions to upgrade. The release closes a critical heap overflow that can be triggered through a specific regex-map request path.

    Show sources