CRITICAL: F5 Patches Two NGINX Flaws Handing Unauthenticated RCE to Remote Attackers
F5 disclosed two critical NGINX vulnerabilities on June 17, 2026, both scoring CVSS 4.0 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QPACK encoder and CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules. Both are remotely exploitable by unauthenticated attackers and affect a huge swath of the NGINX Open Source and NGINX Plus install base.