Skip to main content
F5Launch

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

What happened

f5 launches security updates to address.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

F5 patches two critical NGINX Open Source flaws enabling remote code execution. F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - * CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. * CVE-2026-42055 (CVSS v4 score: 9.2) - A heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules that could be triggered by a remote unauthenticated attacker when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 MB, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Both shortcomings have been patched in the following versions - * CVE-2026-42530 - * NGINX Open Source 1.31.0 - 1.31.1 (Fixed in...

Keep reading with a free account

The rest of this article, and every signal for F5, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
security updates to address

The full record

From the Signal API record

Details

Release type
Updates
Ticker
NASDAQ:FFIV

Topics and mentions

Product tags

  • security

Extraction

Confidence
80%
Detected
Jun 18, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for F5 and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at F5 this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/7fe4b3f4-c0bb-4c34-a9b0-cb6a18ae5a12 returns this record as JSON. POST /v1/companies/enrich returns every signal for f5.com.

{
  "signal_id": "7fe4b3f4-c0bb-4c34-a9b0-cb6a18ae5a12",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-06-18T00:00:00+00:00",
  "company": {
    "name": "F5",
    "domain": "f5.com"
  },
  "data": {
    "url": "https://bulletproofservers.hk/blog/f5-patches-two-critical-nginx-open-source-flaws-enabling-remote-code-execution",
    "title": "F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution",
    "ticker": "NASDAQ:FFIV",
    "excerpt": "F5 patches two critical NGINX Open Source flaws enabling remote code execution.\n\nF5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.\n\nThe vulnerabilities are listed below -\n\n* CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n* CVE-2026-42055 (CVSS v4 score: 9.2) - A heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules that could be triggered by a remote unauthenticated attacker when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 MB, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n\nBoth shortcomings have been patched in the following versions -\n\n* CVE-2026-42530\n\n-\n\n* NGINX Open Source 1.31.0 - 1.31.1 (Fixed in...",
    "product": "security updates to address",
    "summary": "f5 launches security updates to address.",
    "planning": false,
    "image_url": "https://bulletproofservers.hk/blog/wp-content/uploads/2026/02/bug.png",
    "confidence": 0.8015,
    "product_data": {
      "full_text": "security updates to address",
      "fuzzy_match": true,
      "release_type": "updates"
    },
    "product_tags": [
      "security"
    ],
    "published_at": "2026-06-18T00:00:00Z",
    "article_sentence": "F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.