The main risk here is not a guaranteed shell. CVE-2026-42533 can become code execution only on systems with ASLR disabled, but the same patch set also covers flaws that can restart workers, leak memory, or let attackers change configuration and knock over the service.
F5 pushed an out-of-band fix for eight NGINX and BIG-IP vulnerabilities. The affected products include NGINX Plus, NGINX Open Source, NGINX Ingress Controller, and BIG-IP, with the highest-risk issue in NGINX triggered by crafted HTTP requests and the rest spanning worker crashes, memory exposure, configuration abuse, and denial of service.