Tuesday , September 29 2026
F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and cause denial-of-service (DoS) attacks in affected systems.

The notice, published on June 17, 2026, points out important problems affecting NGINX Open Source, NGINX Plus, and related products like NGINX Gateway Fabric and NGINX Ingress Controller.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Some of these flaws have CVSS v4.0 scores up to 9.2, showing a big risk to organizations using NGINX for web and app delivery. One serious flaw, known as CVE-2026-42530, affects the ngx_http_v3_module in NGINX. This issue impacts NGINX Open-Source versions 1.31.0 and 1.31.1 and has been fixed in version 1.31.2.

Successful exploitation might cause memory issues, which could allow remote code to run or disrupt services. Another serious problem, CVE-2026-42055, affects the ngx_http_proxy_v2_module and ngx_http_grpc_module.

This flaw impacts both NGINX Open Source and NGINX Plus setups. Security experts say that attackers might use this weakness to cause DoS issues or run harmful code in certain situations.

F5 Patches NGINX Vulnerability

The flaw has been fixed in NGINX Open Source versions 1.30.3 and 1.31.2, and in NGINX Plus release 37.0.2.1 and R36 P6.

F5 revealed more issues in NGINX Gateway Fabric, including CVE-2026-11311 and CVE-2026-50107, which are both serious. These problems affect versions 2.3.0 to 2.6.3 and are fixed in version 2.6.4.

Exploitation of these issues could result in service instability or unauthorized behavior within Kubernetes-based environments where Gateway Fabric is deployed.
In addition to high-severity flaws, the advisory includes medium-severity vulnerabilities such as CVE-2026-48142, which affects the ngx_http_charset_module.

This issue may not be very important, but it can still affect how the application works or lower service reliability if not fixed.

Several F5 and NGINX products, like NGINX Instance Manager, NGINX App Protect, and F5 WAF for NGINX, are affected but do not have direct fixes yet.

F5 suggests using fixes and checking settings until updates are available for these parts.

F5 Advisory K000161614 says that systems open to the internet are very risky and need to be updated right away with the latest fixes.

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …