• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

F5 Patches NGINX Vulnerability Enabling Code Execution and DoS Assaults

Admin by Admin
June 19, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


F5 has launched an out-of-band safety notification addressing a number of excessive‑severity vulnerabilities in NGINX elements that may allow distant code execution (RCE) and denial‑of‑service (DoS) assaults in sure configurations, urging clients to patch or improve affected deployments instantly.

On June 17, 2026, F5 issued an out-of-band safety notification (K000161614) summarizing a number of high- and medium-severity flaws throughout NGINX Open Supply, NGINX Plus, NGINX Occasion Supervisor, NGINX Gateway Material, NGINX Ingress Controller, and related App Shield WAF/DoS modules.

The advisory, up to date on June 18, 2026, highlights the elevated danger to HTTP/2, HTTP/3, and gRPC visitors dealing with paths and offers clients with a consolidated view of impacted merchandise, variations, and stuck releases.

This notification dietary supplements F5’s common Quarterly Safety Notifications and is being echoed by nationwide CERTs, underscoring its urgency.

Vital NGINX HTTP/3 v3 Module Flaw (CVE-2026-42530)

Probably the most outstanding problem, tracked as CVE-2026-42530 and detailed in F5 article K000161616, impacts the NGINX ngx_http_v3_module when NGINX is configured to make use of the HTTP/3 QUIC module.

A distant, unauthenticated attacker can ship specifically crafted HTTP/3 visitors to reopen a QPACK encoder stream, triggering a use-after-free within the NGINX employee course of that may repeatedly crash employees, inflicting DoS, and doubtlessly permitting code execution on techniques the place ASLR is disabled or could be bypassed.

F5 assigns this bug a CVSS v3.1 base rating of 8.1 and a CVSS v4.0 base rating of 9.2, reflecting its high-to-critical affect profile on fashionable deployments.

A second high-severity problem, CVE-2026-42055 (K000161584), targets NGINX Plus and NGINX Open Supply when utilizing the ngx_http_proxy_v2_module or gRPC module with HTTP/2 backends.

When proxy_http_version is about to 2 or gRPC upstreams are enabled, malformed or malicious HTTP/2 or gRPC streams can result in memory-handling flaws that will manifest as crashes and probably code execution, relying on the atmosphere’s hardening.

This flaw can be rated at 8.1 (CVSS v3.1) and 9.2 (CVSS v4.0), aligning it with the HTTP/3 vulnerability by way of severity from F5’s perspective.

F5 moreover discloses a number of high-severity vulnerabilities in NGINX Gateway Material, together with CVE-2026-11311 and CVE-2026-50107, described in K000161611 and K000161785, respectively.

These points have an effect on numerous 2.x Gateway Material releases. They can lead to routing instability, service disruptions, or different impacts on integrity and availability inside service-mesh and gateway deployments. F5 introduces fixes in Gateway Material 2.6.4, which is now the really helpful goal model for affected clients.

Excessive CVE Matrix

Beneath is a consolidated desk of the excessive‑severity CVEs and their core technical metadata as offered by F5, specializing in CVSS scores, affected merchandise, variations, and fixes.

CVE / Article CVSS v3.1 CVSS v4.0 Affected merchandise Affected variations Mounted in
CVE-2026-42530 (K000161616) 8.1 (Excessive) 9.2 (Vital) NGINX Open Supply 1.31.0 – 1.31.1 1.31.2
NGINX Occasion Supervisor 2.17.0 – 2.22.0 None (no repair but)
NGINX Gateway Material 2.0.0 – 2.6.3, 1.3.0 – 1.6.2 2.6.4
NGINX Ingress Controller 5.0.0 – 5.5.0, 4.0.0 – 4.0.1, 3.5.0 – 3.7.2 None (no repair but)
CVE-2026-42055 (K000161584) 8.1 (Excessive) 9.2 (Vital) NGINX Plus 37.0.0 – 37.0.1, R33 – R36 37.0.2.1, R36 P6
NGINX Open Supply 1.31.1, 1.30.0 – 1.30.2 1.31.2, 1.30.3
NGINX Occasion Supervisor 2.17.0 – 2.22.0 None
F5 WAF for NGINX 5.9.0 – 5.13.1 None
NGINX App Shield WAF 5.2.0 – 5.8.0, 4.10.0 – 4.16.0 None
F5 DoS for NGINX 4.9.0 None
NGINX App Shield DoS 4.3.0 – 4.7.0 None
NGINX Gateway Material 2.0.0 – 2.6.3, 1.3.0 – 1.6.2 None
NGINX Ingress Controller 5.0.0 – 5.5.0, 4.0.0 – 4.0.1, 3.5.0 – 3.7.2 None
CVE-2026-11311 (K000161611) 8.1 (Excessive) 8.6 (Excessive) NGINX Gateway Material 2.5.0 – 2.6.3 2.6.4
CVE-2026-50107 (K000161785) 8.1 (Excessive) 8.6 (Excessive) NGINX Gateway Material 2.3.0 – 2.6.3 2.6.4

F5 strongly recommends upgrading NGINX Open Supply to 1.31.2, NGINX Plus to 37.0.2.1 or R36 P6, NGINX Gateway Material to 2.6.4, and aligning Ingress Controller and App Shield elements with forthcoming patched releases as they turn out to be out there.

Organizations unable to patch instantly ought to contemplate turning off HTTP/3 and QUIC help, proscribing HTTP/2 and gRPC publicity, imposing strict entry controls, and hardening ASLR and different exploitation mitigations as interim measures.

Directors are additional suggested to watch F5’s quarterly safety notifications and vendor RSS/e mail channels to trace future updates and any adjustments in exploitation standing.

Comply with us on Google Information, LinkedIn, and X to Get Immediate Updates and Set GBH as a Most well-liked Supply in Google.

Tags: AttacksCodeDOSEnablingExecutionNGINXPatchesVulnerability
Admin

Admin

Next Post
Telegram ban in India sparks a rush to VPNs, rival apps

Telegram ban in India sparks a rush to VPNs, rival apps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

The HubSpot Weblog’s AI Traits for Entrepreneurs Report [key findings from 1,000+ marketing pros]

The HubSpot Weblog’s AI Traits for Entrepreneurs Report [key findings from 1,000+ marketing pros]

June 12, 2025
How To Attain The Floating Island in Metropolis Trial on Kirby Air Raiders

How To Attain The Floating Island in Metropolis Trial on Kirby Air Raiders

November 23, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

August 23, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

AI Regulation Ignored in NYC Hiring

AI Regulation Ignored in NYC Hiring

September 19, 2026
The New Resident Evil Film Feels Like Diving Right into a Misplaced In-Sport File

The New Resident Evil Film Feels Like Diving Right into a Misplaced In-Sport File

September 19, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved