INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

F5 Patches Critical NGINX Vulnerabilities

| 2026-06-18 17:32 CRITICAL MEDIUM
Executive Summary AI-generated
The recent discovery of two critical security vulnerabilities in NGINX Open Source and F5 products has raised significant concerns about the potential for exploitation by malicious actors. These flaws, identified as CVE-2026-42530 and CVSS v4 score 9.2, can be exploited to achieve code execution on affected systems. The vulnerabilities are linked to specific directives in configuration files, such as ignore_invalid_headers off directive or large_client_header_buffers size above 2 MB. F5 has released security updates to address these issues, but the timeline for widespread deployment is uncertain due to the complexity of mitigating these types of attacks.
Technical Mitigations AI-generated
* Disable HTTP/3: Disabling HTTP/3 can prevent remote code execution attacks, but it may also impact performance and compatibility with certain applications. * Remove ignore_invalid_headers directive or reduce large_client_header_buffers size below 2 MB for CVE-2026-42055 vulnerabilities. This will help mitigate the risk of heap-based buffer overflow attacks. * Use a secure configuration: Ensure that NGINX is configured to use secure protocols (e.g., HTTPS) and limit the number of open connections, which can reduce the attack surface. * Keep software up-to-date: Regularly update F5 products and other dependencies to ensure you have the latest security patches and fixes.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42945CVE-2026-42945 CVE-2026-42055CVE-2026-42055 CVE-2026-42530CVE-2026-42530 CVE-2026-50107CVE-2026-50107 CVE-2026-11311CVE-2026-11311
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎August 2025
Threat actors exploited a previously unknown vulnerability in F5's NGINX open source software to gain access to the company's systems.
‎2026/05/19
Threat actors exploited a recently disclosed critical security defect in NGINX Plus and NGINX Open Source, allowing remote code execution.
general_metric 9.2 vulnerabilities
vulnerability CVE-2026-42945
organisation NGINX Plus
organisation NGINX Rift
‎Jun 18, 2026
The threat actors exploited a remote code execution vulnerability in NGINX Ingress Controller 5.0.0 - 5.5.0, which was patched by F5 as of version 37.0.2.1 and later versions.
organisation CVSS
infrastructure 1.31.0
infrastructure 1.31.1
infrastructure 1.31.2
infrastructure 2.0.0
infrastructure 2.6.3
infrastructure 2.6.4
data_breach 2 MB
infrastructure 1.3.0
infrastructure 1.6.2
infrastructure 2.17.0
infrastructure 2.22.0
infrastructure 5.0.0
infrastructure 5.5.0
infrastructure 4.0.0
infrastructure 4.0.1
infrastructure 3.5.0
infrastructure 3.7.2
infrastructure 37.0.0
infrastructure 37.0.1
infrastructure 37.0.2
infrastructure 1.30.0
infrastructure 1.30.2
infrastructure 1.30.3
infrastructure 5.9.0
infrastructure 5.13.1
infrastructure 5.2.0
infrastructure 5.8.0
infrastructure 4.10.0
infrastructure 4.16.0
infrastructure 4.9.0
infrastructure 4.3.0
infrastructure 4.7.0
organisation NGINX Instance
organisation NGINX
organisation CVE-2026-42055 - NGINX Plus
organisation NGINX Plus R33 - R36
organisation NGINX Open Source 1.31.1
organisation NGINX App Protect
organisation ignore_invalid_headers
organisation QPACK
organisation Address Space Layout Randomization
‎2026/06/18
F5 released emergency updates for critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) that could enable unauthenticated code execution.
organisation NGINX
organisation DoS
organisation ignore_invalid_headers
data_breach 2 MB
organisation CVE-2026
organisation NGINX Instance
organisation NGINX Plus
organisation NGINX Open Source
organisation NGINX Gateway Fabric
organisation Vulnerability / Cloud Security
organisation QPACK
organisation Address Space Layout Randomization
organisation SecurityAffairs
organisation ADN
victims 23,000 customers
victims 48 customers
organisation EDR
Tactical Metrics
Metrics
data_breach
2
Mb
Metrics
infrastructure
‎1.31.0
Software Version
Metrics
infrastructure
‎1.31.1
Software Version
Metrics
infrastructure
‎1.31.2
Software Version
Metrics
infrastructure
‎2.0.0
Software Version
Metrics
infrastructure
‎2.6.3
Software Version
Metrics
infrastructure
‎2.6.4
Software Version
Metrics
infrastructure
‎1.3.0
Software Version
Metrics
infrastructure
‎1.6.2
Software Version
Metrics
infrastructure
‎2.17.0
Software Version
Metrics
infrastructure
‎2.22.0
Software Version
Metrics
infrastructure
‎5.0.0
Software Version
Metrics
infrastructure
‎5.5.0
Software Version
Metrics
infrastructure
‎4.0.0
Software Version
Metrics
infrastructure
‎4.0.1
Software Version
Metrics
infrastructure
‎3.5.0
Software Version
Metrics
infrastructure
‎3.7.2
Software Version
Metrics
infrastructure
‎37.0.0
Software Version
Metrics
infrastructure
‎37.0.1
Software Version
Metrics
infrastructure
‎37.0.2
Software Version
Metrics
infrastructure
‎1.30.0
Software Version
Metrics
infrastructure
‎1.30.2
Software Version
Metrics
infrastructure
‎1.30.3
Software Version
Metrics
infrastructure
‎5.9.0
Software Version
Metrics
infrastructure
‎5.13.1
Software Version
Metrics
infrastructure
‎5.2.0
Software Version
Metrics
infrastructure
‎5.8.0
Software Version
Metrics
infrastructure
‎4.10.0
Software Version
Metrics
infrastructure
‎4.16.0
Software Version
Metrics
infrastructure
‎4.9.0
Software Version
Metrics
infrastructure
‎4.3.0
Software Version
Metrics
infrastructure
‎4.7.0
Software Version
Metrics
victims
23,000
Customers
Metrics
victims
48
Customers