F5 Fixes Three High-Severity NGINX Flaws that could Expose Servers to Attacks

Last updated: July 16, 2026 Reading time: 4 minutes
Disclosure
Share
Spain Arrests Suspected Pro-Russia Hacker in FBI-Assisted Operation
  • F5 has fixed three high-severity security flaws affecting NGINX Plus and NGINX Open Source.
  • The bugs could let attackers crash servers, expose sensitive memory, or possibly run harmful code under certain conditions.
  • F5 urges organizations using affected NGINX products to install the latest security updates as soon as possible.

F5 has released security updates after finding three serious security flaws in NGINX Plus and NGINX Open Source. The company warned that attackers could exploit these bugs to compromise server memory, expose sensitive information, or even execute malicious code in some cases.

The security issues became public on July 15, 2026. They affect several products built on the NGINX platform. These include NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and NGINX Instance Manager.

Many businesses rely on NGINX to run websites, online services, and cloud systems. Because of this, security experts say organizations should install the latest updates without delay. The three flaws are tracked as CVE-2026-42533, CVE-2026-60005, and CVE-2026-56434.

One Flaw Could Open the Door to Code Execution

The most serious issue is CVE-2026-42533. It is a heap buffer overflow bug. The flaw appears when NGINX processes specially made requests that use the map directive together with regular expressions. A hacker could send a carefully prepared request to trigger the bug. The attack could crash worker processes running on the server.

According to F5, the same flaw could become even more dangerous in some environments. If memory protections are weak or attackers manage to get around them, they may be able to run their own code on the affected system.

The second flaw is CVE-2026-60005. This issue affects the ngx_http_slice_module. This bug can expose pieces of server memory that should stay hidden. An attacker may read uninitialized memory and discover sensitive information stored by the server.

The flaw does not directly let someone run malicious code. However, leaked memory can still help attackers plan future attacks. The exposure of sensitive user data is a recurring theme. Facebook recently revealed a bug that exposed up to 6.8 million users’ unposted photos. It may also help them get around security protections that would normally stop an exploit.

The third issue is CVE-2026-56434. This bug affects the ngx_http_ssi_module. It is a use-after-free vulnerability. An attacker who exploits it could crash worker processes and interrupt normal service.

According to F5, this flaw may also become more serious under certain conditions. Some use-after-free bugs can damage memory and later help attackers execute malicious code. Whether that happens depends on the affected system and how it is configured.

Several NGINX Products Need Updates

F5 said the three security flaws affect both NGINX Plus and NGINX Open Source. The problems also extend to products that use the NGINX platform. These include NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and NGINX Instance Manager.

At the same time, the company confirmed that several other F5 products are not affected. According to F5, BIG-IP, BIG-IQ, F5OS, AI Gateway, and F5 Distributed Cloud Services do not contain these vulnerabilities. Security researchers say memory corruption bugs deserve special attention. These flaws often become valuable targets because attackers sometimes combine them with other weaknesses.

A single flaw may not always lead to a full system takeover. However, several bugs used together can greatly increase the chances of a successful attack. That is why security teams usually treat heap corruption and use-after-free bugs as high-risk issues.

Even information leaks can create problems. Small pieces of exposed memory may reveal details that help attackers build stronger exploits later.

F5 Urges Customers to Patch Affected Systems Quickly

F5 has already released updated versions for the affected products. The company encourages customers to install the security fixes as soon as possible to reduce the risk of attack. Some organizations may need extra time before updating their systems. F5 says those users should carefully review their NGINX setup in the meantime.

According to the company, administrators should pay close attention to servers using the affected map, slice, and Server Side Includes (SSI) modules. They should also watch for unexpected crashes or unusual system behavior that could point to an attempted attack.

The latest disclosure highlights an ongoing challenge for organizations that manage internet-facing systems. NGINX powers millions of websites, cloud services, APIs, and online platforms around the world.

Because of its wide use, security flaws in its core components can affect many organizations if they remain unpatched. F5 recommends that administrators review its official security advisories, identify affected deployments, and apply the recommended updates as quickly as possible. Taking these steps can help lower the chances of attackers exploiting these newly disclosed vulnerabilities.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts