Vulnerability Management F5 fixes critical nginx vulnerability CVE-2026-42533 July 20, 2026 Share By SC Staff (Adobe Stock) Security Affairs reports that F5 has released patches for a critical nginx vulnerability, identified as CVE-2026-42533, which poses a significant risk of server crashes and potential remote code execution. The vulnerability, with a CVSS score of 9.2, allows an unauthenticated attacker to trigger a heap buffer overflow by sending specially crafted HTTP requests. This flaw affects both NGINX Plus and Open Source versions from 0.9.6 through 1.31.2 when specific regex-based map configurations are utilized. While the primary impact is denial of service, researchers suggest that under certain conditions, such as disabled ASLR, remote code execution might be possible. The issue is limited to the data plane. F5 has addressed the vulnerability in NGINX 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1. A temporary workaround involves modifying affected map configurations to use named captures instead of numbered ones, though this does not offer complete protection. The vulnerability was discovered by Mufeed VH and Maxim Dounin, with security researcher Stan Shaw highlighting its potential for remote code execution and releasing a scanner to identify vulnerable configurations. Source: Security Affairs SC Staff Related Vulnerability Management HollowByte vulnerability allows denial-of-service attacks on OpenSSL SC Staff July 20, 2026 The HollowByte vulnerability, detailed by Okta's Red Team, exploits a flaw in how OpenSSL handles TLS handshake messages. Patch/Configuration Management Windows 10 devices carry 3 times the risk of Windows 11, data shows SC Staff July 17, 2026 New data from Lansweeper indicates that approximately 16.9% of Windows client devices, or one in six, continue to operate on Windows 10. Patch/Configuration Management Microsoft pauses Windows 11 update for Dell PCs due to compatibility issues SC Staff July 17, 2026 The update, released on July 14, was halted after reports indicated that a number of Dell devices displayed a yellow exclamation point next to the Intel Innovation Platform Framework Processor Participant driver in Device Manager. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds