← Intelligence Center

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

PublishedMay 18, 2026
Updated
VendorF5 (NGINX)
SeverityHigh
Known ExploitedYes Known Exploited
Advisory IDINTEL-000012
CVEs
CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946
Products
  • NGINX Open Source 0.6.27 through 1.30.0
  • NGINX Plus R32 through R36
  • NGINX Instance Manager 2.16.0 through 2.21.1
  • F5 WAF for NGINX 5.9.0 through 5.12.1
  • NGINX App Protect WAF 4.9.0 through 4.16.0 and 5.1.0 through 5.8.0
  • F5 DoS for NGINX 4.8.0
  • NGINX App Protect DoS 4.3.0 through 4.7.0
  • NGINX Gateway Fabric 1.3.0 through 1.6.2 and 2.0.0 through 2.5.1
  • NGINX Ingress Controller 3.5.0 through 3.7.2, 4.0.0 through 4.0.1, and 5.0.0 through 5.4.1

Executive Summary

MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.

Municipal Impact

MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal web infrastructure using NGINX should be patched urgently.

SMB Impact

MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by F5 or other vendors which use this software to vulnerable systems immediately after appropriate testing.
  2. Prioritize remediation of CVE-2026-42945, which is being exploited in the wild.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

References

Tags

NGINXF5CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946RCEHeap Buffer OverflowUse After FreeOut-of-Bounds ReadTA0001T1190

Related Intelligence

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter