F5 patches critical NGINX vulnerabilities CVE-2026-42530 and CVE-2026-42055 that can crash servers and potentially allow code execution

F5 released emergency updates for NGINX products to fix critical security flaws that can let an unauthenticated attacker crash internet-facing servers and, in some cases, potentially run malicious code. The main issues are CVE-2026-42530 and CVE-2026-42055, both rated 9.2, affecting HTTP modules in NGINX Plus, NGINX Open Source, and NGINX Gateway Fabric; exploitation can trigger worker-process restarts, and arbitrary code execution may be possible if Address Space Layout Randomization (a memory-protection feature) is disabled or bypassed. F5 also patched NGINX Gateway Fabric flaws CVE-2026-11311 and CVE-2026-50107 that let authenticated attackers inject NGINX configuration directives.
Why it matters: Organizations using NGINX to run websites, APIs, or application gateways may be exposed to denial-of-service and possible remote compromise, especially on internet-facing systems. Administrators should identify affected NGINX deployments and apply F5's out-of-band updates promptly.

Sources

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
info@thehackernews.com (The Hacker News) 2026.06.18 99% relevant
This article reports the same F5/NGINX patch event for the two critical open source NGINX flaws, adding another source confirming the vulnerabilities' severity and remote exploitation risk.
F5 issues out-of-band patches for critical NGINX vulnerabilities
Sergiu Gatlan 2026.06.18 98% relevant
This article covers the same F5 out-of-band patch release for the same two critical NGINX flaws and adds product-level detail on affected software including NGINX Plus, NGINX Open Source, NGINX Gateway Fabric, and NGINX Instance Manager, along with mitigation steps and mention of two additional high-severity Gateway Fabric issues.
F5 Patches Critical, High-Severity NGINX Vulnerabilities
Ionut Arghire 2026.06.18 100% relevant
This article establishes a distinct new patching event for multiple newly disclosed NGINX vulnerabilities and does not match any existing tracked story about the same CVEs or release.
← Back to all stories