F5 Patches 8 NGINX and BIG-IP Flaws, Including 9.2-Rated Bug
Updated
Updated · SecurityWeek · Jul 16
F5 Patches 8 NGINX and BIG-IP Flaws, Including 9.2-Rated Bug
2 articles · Updated · SecurityWeek · Jul 16
Summary
An out-of-band F5 update fixes eight critical and high-severity vulnerabilities across NGINX, NGINX Ingress Controller and BIG-IP, with the most severe issue tracked as CVE-2026-42533.
CVE-2026-42533 carries a 9.2 CVSS score and lets unauthenticated attackers send crafted HTTP requests that trigger a heap buffer overflow and restart NGINX worker processes; with ASLR disabled, it can lead to code execution.
Several other high-severity NGINX flaws can be exploited without authentication to leak memory, cause use-after-free conditions, modify memory or repeatedly restart worker processes.
Two NGINX Ingress Controller bugs let authenticated attackers inject arbitrary NGINX directives, delete files, disable services or create resources that trigger denial-of-service conditions.
A separate high-severity BIG-IP flaw allows remote unauthenticated attackers to drive up memory use on virtual servers with HTTP/2 enabled, causing DoS; F5 said none of the issues are known to be exploited in the wild.