Thursday , July 30 2026
F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and cause denial-of-service (DoS) attacks in affected systems.

The notice, published on June 17, 2026, points out important problems affecting NGINX Open Source, NGINX Plus, and related products like NGINX Gateway Fabric and NGINX Ingress Controller.

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Some of these flaws have CVSS v4.0 scores up to 9.2, showing a big risk to organizations using NGINX for web and app delivery. One serious flaw, known as CVE-2026-42530, affects the ngx_http_v3_module in NGINX. This issue impacts NGINX Open-Source versions 1.31.0 and 1.31.1 and has been fixed in version 1.31.2.

Successful exploitation might cause memory issues, which could allow remote code to run or disrupt services. Another serious problem, CVE-2026-42055, affects the ngx_http_proxy_v2_module and ngx_http_grpc_module.

This flaw impacts both NGINX Open Source and NGINX Plus setups. Security experts say that attackers might use this weakness to cause DoS issues or run harmful code in certain situations.

F5 Patches NGINX Vulnerability

The flaw has been fixed in NGINX Open Source versions 1.30.3 and 1.31.2, and in NGINX Plus release 37.0.2.1 and R36 P6.

F5 revealed more issues in NGINX Gateway Fabric, including CVE-2026-11311 and CVE-2026-50107, which are both serious. These problems affect versions 2.3.0 to 2.6.3 and are fixed in version 2.6.4.

Exploitation of these issues could result in service instability or unauthorized behavior within Kubernetes-based environments where Gateway Fabric is deployed.
In addition to high-severity flaws, the advisory includes medium-severity vulnerabilities such as CVE-2026-48142, which affects the ngx_http_charset_module.

This issue may not be very important, but it can still affect how the application works or lower service reliability if not fixed.

Several F5 and NGINX products, like NGINX Instance Manager, NGINX App Protect, and F5 WAF for NGINX, are affected but do not have direct fixes yet.

F5 suggests using fixes and checking settings until updates are available for these parts.

F5 Advisory K000161614 says that systems open to the internet are very risky and need to be updated right away with the latest fixes.

Check Also

SolarWinds

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix …