Is Your NGINX Server Truly Secure? F5 Warns of Critical Vulnerabilities That Could Lead to Remote Code Execution!

Imported from official source

Announcement

F5 has issued an official security advisory regarding several high-risk vulnerabilities affecting NGINX Plus and NGINX Open Source. According to security experts, successful exploitation of these vulnerabilities could result in memory corruption, denial of service (DoS), and, in certain cases, remote code execution (RCE).

The identified vulnerabilities affect widely deployed components, including NGINX Plus, NGINX Open Source, NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and NGINX Instance Manager. Since these products are extensively used to power internet-facing web applications, API services, container platforms, and cloud environments, security professionals strongly recommend applying the available updates without delay.

Most Critical Vulnerability — CVE-2026-42533

The most severe vulnerability identified is CVE-2026-42533, which has been assigned a CVSS v3.1 score of 8.1 and a CVSS v4.0 score of 9.2.

This vulnerability is a Heap Buffer Overflow caused by a logic flaw in the way NGINX processes the map directive and regular expressions (regex).

By sending specially crafted HTTP requests, an attacker can corrupt the memory of an NGINX Worker Process.

  • Causing Worker Processes to terminate unexpectedly;
  • Remote execution of arbitrary code on systems where Address Space Layout Randomization (ASLR) is absent or has been bypassed.
  • As a temporary mitigation, F5 recommends using named regex captures instead of unnamed regex captures.

    CVE-2026-60005 — Information Disclosure from Uninitialized Memory

    The second vulnerability, CVE-2026-60005, has received a CVSS v3.1 score of 8.2 and a CVSS v4.0 score of 8.8.

    The issue exists in the ngx_http_slice_module, which is not enabled by default and is only available in systems compiled with a specific build option.

  • Disclosure of data from uninitialized memory;
  • Leakage of limited amounts of sensitive information;
  • F5 also recommends using named regex captures as a mitigation for this issue.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/is-your-nginx-server-truly-secure-f5-warns-of-critical-vulnerabilities-that-could-lead-to-remote-code-execution/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39214

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.