Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution
- •NGINX Open Source 0.6.27 through 1.30.0
- •NGINX Plus R32 through R36
- •NGINX Instance Manager 2.16.0 through 2.21.1
- •F5 WAF for NGINX 5.9.0 through 5.12.1
- •NGINX App Protect WAF 4.9.0 through 4.16.0 and 5.1.0 through 5.8.0
- •F5 DoS for NGINX 4.8.0
- •NGINX App Protect DoS 4.3.0 through 4.7.0
- •NGINX Gateway Fabric 1.3.0 through 1.6.2 and 2.0.0 through 2.5.1
- •NGINX Ingress Controller 3.5.0 through 3.7.2, 4.0.0 through 4.0.1, and 5.0.0 through 5.4.1
Executive Summary
MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.
Municipal Impact
MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal web infrastructure using NGINX should be patched urgently.
SMB Impact
MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.
Recommended Actions
- Apply appropriate updates provided by F5 or other vendors which use this software to vulnerable systems immediately after appropriate testing.
- Prioritize remediation of CVE-2026-42945, which is being exploited in the wild.
- Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.
Grey Matter Analysis
References
- https://learn.cisecurity.org/e/799323/a-an-18-year-old-vulnerability/4vxh5c/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/manage-s-article-K000161019/4vxh58/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/ow-queries-and-signatures-only/4vxh5g/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-40701/4vxh5v/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-42934/4vxh5k/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-42945/4vxh5n/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-42946/4vxh5r/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vxh4g/2694412600/h/uua0U9ItmG68DeybXRwegBK_Ini0SxGtplb-RgTzp5c
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter