Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/CyberSecurity News/F5 Patches Critical NGINX Vulnerability CVE-2023-50438
CyberSecurity News

F5 Patches Critical NGINX Vulnerability CVE-2023-50438

Key Takeaways F5 has released an urgent out-of-band security advisory addressing several critical and high-severity vulnerabilities in NGINX products. The flaws affect NGINX Open Source, NGINX Plus,...

Jennifer sherman
Jennifer sherman
June 18, 2026 3 Min Read
48 0

Key Takeaways

  • F5 has released an urgent out-of-band security advisory addressing several critical and high-severity vulnerabilities in NGINX products.
  • The flaws affect NGINX Open Source, NGINX Plus, NGINX Gateway Fabric, and NGINX Ingress Controller.
  • Attackers could exploit these vulnerabilities to achieve remote code execution, memory corruption, or denial-of-service (DoS) conditions.
  • Patches are available for most affected core NGINX components, with CVSS v4.0 scores reaching up to 9.2.
  • Organizations are strongly advised to update immediately and apply mitigations for products awaiting direct fixes.

F5 has issued an urgent out-of-band security advisory, detailing multiple high-severity vulnerabilities discovered across its NGINX product line. These critical flaws could potentially allow malicious actors to execute arbitrary code remotely or launch debilitating denial-of-service (DoS) attacks against affected systems.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Detailed
  • F5 Releases Patches and Mitigations
  • What You Should Do

Published on June 17, 2026, the advisory highlights significant risks impacting NGINX Open Source, NGINX Plus, and related offerings such as NGINX Gateway Fabric and NGINX Ingress Controller.

Several of the identified vulnerabilities carry CVSS v4.0 scores as high as 9.2, underscoring the severe threat they pose to organizations that depend on NGINX for their web and application delivery infrastructure.

Critical Vulnerabilities Detailed

One of the most pressing issues, identified as CVE-2026-42530, resides within the ngx_http_v3_module of NGINX. This particular vulnerability impacts NGINX Open Source versions 1.31.0 and 1.31.1 and has since been addressed in version 1.31.2.

Successful exploitation of CVE-2026-42530 could result in memory corruption, opening avenues for remote code execution or significant service disruptions. Another notable high-risk vulnerability, CVE-2026-42055, affects both the ngx_http_proxy_v2_module and ngx_http_grpc_module.

This flaw impacts both NGINX Open Source and NGINX Plus deployments. Cybersecurity researchers caution that attackers could leverage this vulnerability to trigger DoS conditions or execute arbitrary malicious code, particularly under specific configuration settings.

F5 Releases Patches and Mitigations

F5 has released fixes for the most critical NGINX vulnerabilities. NGINX Open Source versions 1.30.3 and 1.31.2 contain resolutions, as do NGINX Plus release 37.0.2.1 and R36 P6.

The advisory also revealed additional high-severity vulnerabilities in NGINX Gateway Fabric, specifically CVE-2026-11311 and CVE-2026-50107. These issues affect versions 2.3.0 through 2.6.3 and have been mitigated in version 2.6.4.

Exploiting these Gateway Fabric vulnerabilities could lead to service instability or unauthorized operations within Kubernetes environments where the fabric is deployed.

Beyond the critical and high-severity flaws, the advisory also includes medium-severity vulnerabilities, such as CVE-2026-48142, which affects the ngx_http_charset_module. While less severe, this issue could still be exploited to alter application behavior or degrade service reliability if left unpatched.

It is important to note that several related F5 and NGINX products, including NGINX Instance Manager, NGINX App Protect, and F5 WAF for NGINX, are also affected but do not yet have direct patches available. F5 recommends implementing interim mitigations and closely monitoring configurations for these components until official fixes are released.

Security experts stress the widespread deployment of NGINX in modern web infrastructure, making these vulnerabilities especially attractive targets for cyber attackers. The F5 Advisory K000161614 explicitly warns that internet-facing systems are at the highest risk and must be updated to the latest patched versions without delay.

For situations where immediate upgrades are not feasible, administrators are advised to implement temporary mitigations, such as restricting network access, disabling vulnerable modules, and diligently monitoring system logs for any suspicious activities. This out-of-band release highlights the critical nature of these vulnerabilities and their potential impact on production systems. Given the combination of remote exploitation potential and high severity scores, prompt patching is essential to reduce the overall attack surface.

F5 continues to provide ongoing updates and comprehensive technical guidance via its official advisory portal. Users are strongly encouraged to subscribe to security notifications to remain informed about future vulnerabilities.

What You Should Do

  • Immediately Apply Patches: Update NGINX Open Source to versions 1.30.3 or 1.31.2, NGINX Plus to release 37.0.2.1 or R36 P6, and NGINX Gateway Fabric to version 2.6.4.
  • Implement Mitigations: For affected products without direct patches (e.g., NGINX Instance Manager, NGINX App Protect, F5 WAF for NGINX), apply recommended temporary mitigations such as restricting access, disabling vulnerable modules, and enhancing log monitoring.
  • Monitor Systems: Continuously monitor logs for any signs of suspicious activity or attempted exploitation, especially on internet-facing NGINX deployments.
  • Stay Informed: Subscribe to F5 security notifications and regularly check the official F5 advisory portal for further updates and guidance.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Evilginx AiTM Attack Steals Microsoft Credentials, MFA, and Sessions

Next Post

Critical Cisco ISE Bug (CVE-2023-20100) Lets Attackers Remotely Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us