vulnerability
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
Critical
Summary
F5 has released security patches to address two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in its NGINX Open Source and NGINX Plus products. These vulnerabilities, which allow for remote code execution, stem from use-after-free and heap-based buffer overflow issues. The flaws are particularly concerning given the widespread use of F5's products in various network infrastructure deployments, and the history of exploitation of similar vulnerabilities in the past.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
