F5 released patches for two critical remote code execution vulnerabilities in NGINX Open Source and NGINX Plus: CVE-2026-42530, a use-after-free flaw in the HTTP/3 QUIC module, and CVE-2026-42055, a heap-based buffer overflow in HTTP/2 proxy modules. Both issues carry a CVSS 9.2 rating and can be exploited remotely without authentication under specific configurations, potentially affecting a broad set of F5 NGINX products including NGINX Plus, Ingress Controller, Gateway Fabric, Instance Manager, and App Protect WAF.
F5 said the flaws were fixed in NGINX Open Source 1.31.2 and 1.30.3 and published mitigations for organizations that cannot patch immediately, including disabling HTTP/3, restoring ignore_invalid_headers to its default behavior, and reducing large_client_header_buffers sizes. A related Apache HTTP Server security update was also issued by EG-FinCIRT, underscoring continued patching activity around widely deployed web server infrastructure, although no active exploitation of the NGINX flaws had been confirmed at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
F5 released patches for two critical NGINX vulnerabilities, CVE-2026-42530 and CVE-2026-42055, affecting NGINX Open Source, NGINX Plus, and related products. Fixes were provided in NGINX Open Source 1.31.2 and 1.30.3, along with mitigations such as disabling HTTP/3 and adjusting header handling settings.
EG-FinCIRT published an Apache HTTP Server security update notice dated 09 June 2026. The reference provides no further synopsis or event details beyond the publication of the update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.