VulnerabilityBleeping Computer
8.1 — CRITICAL
F5 issues out-of-band patches for critical NGINX vulnerabilities
Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
F5 has released out-of-band patches for multiple NGINX web server vulnerabilities, including two critical-severity flaws that can allow attackers to execute code on vulnerable systems. These vulnerabilities have been exploited by both cybercrime and nation-state threat groups in recent years.
⚙️Technical Details
CVEs
CVE-2026-42530CVE-2026-42055CVE-2026-11311CVE-2026-50107
Affected Systems
NGINX PlusNGINX Open SourceNGINX Gateway FabricNGINX Instance Manager
Attack Vectors
unauthenticated remote attackers (CVE-2026-42530, CVE-2026-42055)authenticated attackers (CVE-2026-11311, CVE-2026-50107)
💥Impact Assessment
Severity: critical
Who Is at Risk
NGINX users worldwide
🛡️Recommended Actions
1Disable HTTP/3 and remove the ignore_invalid_headers off directive from the configuration to mitigate CVE-2026-42530
2Remove the ignore_invalid_headers off directive from the configuration and reduce the large_client_header_buffers directive size below 2 megabytes to mitigate CVE-2026-42055
3Apply the latest security updates for NGINX Gateway Fabric to address CVE-2026-11311 and CVE-2026-50107
📦Affected Products
NGINX PlusNGINX Open SourceNGINX Gateway FabricNGINX Instance Manager
🔐NVD Verified DataVERIFIED
CVE-2026-50107 ↗CVSS 8.1 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NWeaknesses
CWE-74
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
