Drooid Logo
Back to today’s briefing

Story perspectives

F5 patches critical nginx RCE flaw; 10/10 exploits succeed

7/20/2026

40 6 Full Breakdown

1 of 1

Story summary
  • F5 issued patches for CVE-2026-42533 on July 15, updating nginx to 1.30.4, 1.31.3 and NGINX Plus to 37.0.3.1.
  • The flaw is a two-pass script engine regex map that overwrites PCRE capture state, creating a buffer that enables overflow, denial-of-service and remote code execution.
  • F5 notes that 10 out of 10 exploits succeeded on Ubuntu 24.04 with glibc 2.39 and ASLR enabled, and that only the patch fully mitigates the issue.