F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code execution. The company states that no active exploitation of these vulnerabilities has been detected.
F5 announced on Wednesday the release of out-of-band security updates to address eight vulnerabilities within its NGINX and BIG-IP products. The most severe vulnerability, CVE-2026-42533, is a critical heap buffer overflow in NGINX Plus and NGINX Open Source, exploitable through crafted HTTP requests. This vulnerability requires Address Space Layout Randomization (ASLR) to be disabled for successful exploitation.
F5’s updates also address several high-severity issues within the NGINX Ingress Controller, allowing authenticated attackers to inject malicious NGINX configuration directives, potentially leading to file deletion and service disruption. Another high-severity issue affects BIG-IP, enabling unauthenticated attackers to increase memory resource utilization via HTTP/2 profile configuration, resulting in a denial-of-service condition.
F5 indicated that no instances of these vulnerabilities being actively exploited in the wild have been identified. The company encourages users to apply these patches immediately to mitigate potential risks.
Related articles include information about vulnerabilities patched by Trend Micro, Tanium, ESET, and Tenable, as well as vulnerabilities addressed by Fortinet, Ivanti, and ServiceNow. Additionally, the article highlights the importance of patching vulnerabilities fixed in Siemens, Schneider, and Rockwell within the context of ICS Patch Tuesday.