CVE-2026-42533
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità ed exploit
Il punto non è un remote shell garantito. Su NGINX, la falla critica diventa code execution solo se ASLR è disattivato; negli altri casi il colpo si ferma più spesso a un worker che si riavvia, memoria esposta o configurazioni alterate, con un impatto comunque sufficiente a far cadere il front door.
F5 ha rilasciato un bundle fuori ciclo per otto vulnerabilità tra NGINX e BIG-IP. La più grave è CVE-2026-42533 in NGINX Plus e NGINX Open Source; colpisce anche NGINX Ingress Controller e una falla su BIG-IP può portare a DoS quando è configurato HTTP/2 su un virtual server.
Per chi gestisce reverse proxy o virtual server esposti, la priorità è verificare lo stato delle patch su più piani di controllo, non inseguire una sola CVE. Un bug che sembra “solo crash” può comunque interrompere il traffico o aprire la strada a abuso di configurazione, e su host senza ASLR il salto a code execution resta concreto.
3 fonti · 20 lug
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Patch Microsoft: CBL-Mariner Releases.
The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 patches CVE-2026-42533, a regex map heap overflow that crashes nginx workers and may allow RCE in specific configurations.
originaleCSIRT Italia / ACN
Risolte vulnerabilità nei prodotti NGINX
Rilevate nuove vulnerabilità, di cui tre gravità “alta”, in NGINX, noto software open source per la gestione del traffico e degli applicativi web.
originaleSecurityWeek
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
originalePart of the PlainSec briefing for 2026-07-19
Every edition of this story: Patch fuori ciclo su NGINX e BIG-IP