F5 patches multiple critical NGINX and BIG‑IP bugs
F5 released out-of-band patches for eight NGINX and BIG‑IP vulnerabilities, including CVE-2026-42533, a heap overflow that can enable code execution if ASLR is disabled.
F5 released out-of-band patches on Wednesday for eight vulnerabilities affecting NGINX and the BIG-IP application delivery platform.
The most severe issue, CVE-2026-42533, carries a CVSS score of 9.2. It is a heap buffer overflow in NGINX Plus and NGINX Open Source that can be triggered by crafted HTTP requests when a map directive uses regex matching and a string expression references the map’s regex capture variables before the map output variable, or when a non-cacheable variable is used in certain string expressions. The flaw can be exploited without authentication under conditions the attacker cannot control. On systems where Address Space Layout Randomization is disabled, successful exploitation may allow arbitrary code execution.
Patches also address high-severity flaws in the ngx_http_slice_module and ngx_http_ssi_module that can be triggered without authentication. Exploitation of those bugs could leak memory contents, restart an NGINX worker process, or cause a use-after-free that modifies memory or forces a process restart.
Two high-severity defects in the NGINX Ingress Controller require authentication. An attacker with credentials could inject NGINX configuration directives to remove files and disable services, or create or modify Ingress or TransportServer resources in ways that lead to denial-of-service.
The updates for BIG-IP fix a high-severity defect that remote, unauthenticated attackers could exploit to increase memory usage on systems that have an HTTP/2 profile configured on a virtual server. Excess memory use could cause a denial-of-service.
F5 published an out-of-band security advisory that provides technical details and the updated builds. The affected products include NGINX Open Source, NGINX Plus, the NGINX Ingress Controller for Kubernetes, and the BIG-IP platform.
F5 reported no evidence of exploitation in the wild at the time of the advisory.
Administrators can consult F5’s advisory for the specific conditions that trigger each defect and for instructions to apply the fixes.








