CVE-2026-42533
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità · 72 giorni fa
Il punto non è un remote shell garantito. Su NGINX, la falla critica diventa code execution solo se ASLR è disattivato; negli altri casi il colpo si ferma più spesso a un worker che si riavvia, memoria esposta o configurazioni alterate, con un impatto comunque sufficiente a far cadere il front door.
F5 ha rilasciato un bundle fuori ciclo per otto vulnerabilità tra NGINX e BIG-IP. La più grave è CVE-2026-42533 in NGINX Plus e NGINX Open Source; colpisce anche NGINX Ingress Controller e una falla su BIG-IP può portare a DoS quando è configurato HTTP/2 su un virtual server.
Per chi gestisce reverse proxy o virtual server esposti, la priorità è verificare lo stato delle patch su più piani di controllo, non inseguire una sola CVE. Un bug che sembra “solo crash” può comunque interrompere il traffico o aprire la strada a abuso di configurazione, e su host senza ASLR il salto a code execution resta concreto.
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Patch Microsoft: CBL-Mariner Releases.
3 fonti che coprono questa storia
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 patches CVE-2026-42533, a regex map heap overflow that crashes nginx workers and may allow RCE in specific configurations.
Risolte vulnerabilità nei prodotti NGINX
Rilevate nuove vulnerabilità, di cui tre gravità “alta”, in NGINX, noto software open source per la gestione del traffico e degli applicativi web.
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
Part of the PlainSec briefing for 2026-07-19