F5 Releases Security Advisory for Critical Vulnerability in NGINX and NGINX Plus
Successful exploitation of CVE-2026-42533 could allow an unauthenticated remote attacker to cause a denial-of-service condition or potentially achieve remote code execution on a targeted system
Summary
Successful exploitation of CVE-2026-42533 could allow an unauthenticated remote attacker to cause a denial-of-service condition or potentially achieve remote code execution on a targeted system
Threat details
Proof-of-concept exploit in testing environments
Security researchers have published detailed technical analysis describing exploitation techniques and reported reliable proof-of-concept exploitation in testing environments. F5 advises that successful exploitation may create a denial-of-service condition and, in some circumstances, remote code execution.
NHS England National CSOC assess that future exploitation is likely.
Introduction
F5 has released a security advisory to address a critical vulnerability in NGINX Open Source and NGINX Plus. Successful exploitation could allow an unauthenticated remote attacker to trigger a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution.
- CVE-2026-42533 - Heap-based Buffer Overflow vulnerability - CVSSv4 Base Score: 9.2
Note: Attackers could execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Remediation advice
Affected organisations are encouraged to review F5 advisory NGINX map directive and regex matching vulnerability CVE-2026-42533 (K000162097) and apply the relevant update as soon as possible. Organisations should additionally identify NGINX deployments using regex-based map directives and ensure use of named captures only when using the map directive.
Definitive source of threat updates
Last edited: 20 July 2026 2:06 pm