← All stories
● Covered by 1 source · 1 reportHigh impact

F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution

Aggregated by BrevFeed security · updated 22h ago
🔖 Save

F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.

Key points

Overview of the Vulnerability

F5 has addressed a critical vulnerability in NGINX designated as CVE-2026-42533. This flaw permits unauthenticated attackers to exploit a heap buffer overflow in the worker process by sending crafted HTTP requests, potentially leading to service disruptions and remote code execution.

Details of the Exploit

The vulnerability arises from specific configurations involving regex-based maps where an output variable is referenced following a regex match. The defect can cause the buffer allocated during request processing to be incorrectly sized, allowing for an attacker to overwrite the buffer and control the flow of execution.

Impact Assessment

F5 rates the CVE-2026-42533 with a CVSS v4 score of 9.2, indicating severe risk. The flaw primarily affects versions of NGINX prior to the patched releases, illustrating the need for users to update to the latest versions to mitigate the risk.

Affected Products and Recommendations

The vulnerability threatens various NGINX products, including the NGINX Ingress Controller and NGINX Plus. Users are advised to upgrade to the specified patched versions to ensure protection against potential exploits. F5 has yet to provide fixes for the other affected products at this time.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

Primary sources

GitHub 0xCyberstan/CVE-2026-42533-Config-Scanner CVE CVE-2026-425338.1 HIGH CVE CVE-2026-429458.1 HIGH CVE CVE-2026-92568.1 HIGH

Reporting from

F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.