F5 has disclosed multiple vulnerabilities affecting NGINX product lines, including NGINX Open Source, NGINX Plus, NGINX Gateway Fabric, and NGINX Ingress Controller, with the most serious issue tracked as CVE-2026-42533. The flaw can lead to remote code execution, while additional reported weaknesses include information disclosure and security restriction bypass across several version ranges. National cybersecurity authorities in Europe have highlighted the breadth of affected products and the severity of the exposure.
F5 released fixes on 2026-07-15 and urged customers to update immediately, warning that the vulnerable configuration is considered typical even if not every deployment is affected. Authorities also noted that proof-of-concept exploit code is already public, raising the likelihood of opportunistic attacks despite no confirmed large-scale exploitation so far. Where immediate patching is not possible, temporary mitigations are available, but vendor-recommended upgrades to fixed versions remain the primary remediation step.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
F5 released security updates for multiple NGINX and F5 NGINX-related products, including fixes for the critical remote code execution flaw CVE-2026-42533. The vendor advised customers to update immediately and noted mitigations were available if patching could not be done at once.
Proof-of-concept exploit code for CVE-2026-42533 was published, increasing the risk of exploitation. The notice said no large-scale exploitation had yet been observed at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcekyberturvallisuuskeskus.fi
Open sourceboho.or.kr
Open sourceacn.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.