Story perspectives
F5 patches critical nginx RCE flaw; 10/10 exploits succeed
7/20/2026
1 of 1
Story summary
- F5 issued patches for CVE-2026-42533 on July 15, updating nginx to 1.30.4, 1.31.3 and NGINX Plus to 37.0.3.1.
- The flaw is a two-pass script engine regex map that overwrites PCRE capture state, creating a buffer that enables overflow, denial-of-service and remote code execution.
- F5 notes that 10 out of 10 exploits succeeded on Ubuntu 24.04 with glibc 2.39 and ASLR enabled, and that only the patch fully mitigates the issue.
