Vulnerabilities · 57 days ago

NGINX Patch Bundle Includes ASLR-Dependent RCE

The main risk here is not a guaranteed shell. CVE-2026-42533 can become code execution only on systems with ASLR disabled, but the same patch set also covers flaws that can restart workers, leak memory, or let attackers change configuration and knock over the service.

F5 pushed an out-of-band fix for eight NGINX and BIG-IP vulnerabilities. The affected products include NGINX Plus, NGINX Open Source, NGINX Ingress Controller, and BIG-IP, with the highest-risk issue in NGINX triggered by crafted HTTP requests and the rest spanning worker crashes, memory exposure, configuration abuse, and denial of service.

CVE-2026-42533

NVD KEV

CVSS 8.1 HIGH: a vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string… Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: F5

Part of the PlainSec briefing for 2026-07-19

Editions

Related stories