F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

2026-06-19T01:24:12Zfab6711ab0a7c30b9f96f2c47d3a6d6dafabec8cca577cf893282e5049f7b264
actively-exploitedandroid-trojancisco-sd-wanf5fortinetfortisandboxgoogle-vertex-aiinc-ransomwarejetbrainsjoomlaliteSpeedmicrosoft-defendernginxnpmprivilege-escalationransomwareremote-code-executionsupply-chainuse-after-free

What happened

Multiple high‑risk vulnerabilities and active exploitation incidents reported across widely used infrastructure and software. F5 released updates addressing two critical NGINX Open Source flaws including a use‑after‑free in ngx_http_v3_module (CVE-2026-42530) that can lead to unauthenticated remote code execution. Microsoft confirmed a Defender elevation‑of‑privilege zero‑day (RoguePlanet, CVE-2026-50656) with a patch in development. U.S. CISA added the Joomla JCE flaw (CVE-2026-48907, CVSS 10.0) to its KEV catalog for active exploitation; Fortinet FortiSandbox vulnerabilities (CVE-2026-39813,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
fab6711ab0a7c30b9f96f2c47d3a6d6dafabec8cca577cf893282e5049f7b264
Enrichment time
2026-06-19T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution · Baitaphish