Skip to main content

F5 Releases Security Advisory for Critical Vulnerability in NGINX and NGINX Plus

Successful exploitation of CVE-2026-42533 could allow an unauthenticated remote attacker to cause a denial-of-service condition or potentially achieve remote code execution on a targeted system

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-42533 could allow an unauthenticated remote attacker to cause a denial-of-service condition or potentially achieve remote code execution on a targeted system


Threat details

Proof-of-concept exploit in testing environments

Security researchers have published detailed technical analysis describing exploitation techniques and reported reliable proof-of-concept exploitation in testing environments. F5 advises that successful exploitation may create a denial-of-service condition and, in some circumstances, remote code execution.

NHS England National CSOC assess that future exploitation is likely.


Introduction

F5 has released a security advisory to address a critical vulnerability in NGINX Open Source and NGINX Plus. Successful exploitation could allow an unauthenticated remote attacker to trigger a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution.

  • CVE-2026-42533 - Heap-based Buffer Overflow vulnerability - CVSSv4 Base Score: 9.2

Note: Attackers could execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.


Remediation advice

Affected organisations are encouraged to review F5 advisory NGINX map directive and regex matching vulnerability CVE-2026-42533 (K000162097) and apply the relevant update as soon as possible. Organisations should additionally identify NGINX deployments using regex-based map directives and ensure use of named captures only when using the map directive.


Definitive source of threat updates


Last edited: 20 July 2026 2:06 pm