CVE-2026-42533
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Microsoft patch: CBL-Mariner Releases.
Vulnerabilities · 57 days ago
The main risk here is not a guaranteed shell. CVE-2026-42533 can become code execution only on systems with ASLR disabled, but the same patch set also covers flaws that can restart workers, leak memory, or let attackers change configuration and knock over the service.
F5 pushed an out-of-band fix for eight NGINX and BIG-IP vulnerabilities. The affected products include NGINX Plus, NGINX Open Source, NGINX Ingress Controller, and BIG-IP, with the highest-risk issue in NGINX triggered by crafted HTTP requests and the rest spanning worker crashes, memory exposure, configuration abuse, and denial of service.
CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Microsoft patch: CBL-Mariner Releases.
3 sources covering this story
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 patches CVE-2026-42533, a regex map heap overflow that crashes nginx workers and may allow RCE in specific configurations.
Risolte vulnerabilità nei prodotti NGINX
Rilevate nuove vulnerabilità, di cui tre gravità “alta”, in NGINX, noto software open source per la gestione del traffico e degli applicativi web.
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
Part of the PlainSec briefing for 2026-07-19