PatchSiren cyber security CVE debrief
CVE-2026-60065 F5 CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T15:16:47.320Z and has not been modified since then. The NVD entry is currently Analyzed. NGINX Plus MQTT filter module (ngx_stream_mqtt_filter) 7 allows unauthenticated attackers to cause a heap buffer over-read leading to a worker process restart. This data plane issue affects various NGINX Plus versions. Defenders should verify deployments, review vendor advisories, and monitor for suspicious activity. The vulnerability has a CVSS score of 6.3 and is classified as MEDIUM severity. There is no control plane exposure. Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Vendor
- F5
- Product
- NGINX Plus
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-15
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-07-15
- Advisory updated
- 2026-08-10
Who should care
NGINX Plus administrators, F5 customers using affected products, security teams monitoring for potential DoS attacks, and operators responsible for NGINX worker process management should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes reviewing system logs for restart events and implementing compensating controls to detect and prevent exploitation attempts. Additionally, vulnerability management teams should prioritize patching affected systems, and platform administrators should ensure that NGINX Plus deployments are properly configured and secured. Security teams should also monitor for potential attacks and review NGINX Plus configurations to ensure they are not exposed to untrusted networks or users. Asset inventory management teams should verify that affected systems are properly tracked and prioritized for remediation. Rollback and change window management teams should plan for potential downtime during patching and remediation efforts. Source tracking and incident response teams should be prepared to respond to potential exploitation events and review NGINX Plus logs for suspicious activity. Finally, NGINX Plus developers and engineers should review the MQTT filter module implementation to ensure that it is secure and properly validated. NGINX Plus users should also consider disabling the MQTT filter module if not required, and implement additional security controls to prevent exploitation. NGINX Plus administrators should also review the vendor advisory and CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. The CVE record was published on 2026-07-15T15:16:47.320Z and has not been modified since then. The NVD entry is currently Analyzed. NGINX Plus MQTT filter module (ngx_stream_mqtt_filter) 7
Technical summary
The NGINX Plus MQTT filter module (ngx_stream_mqtt_filter_module) is vulnerable to a heap buffer over-read. Unauthenticated attackers can send requests with conditions beyond their control to cause a restart of the NGINX worker process. This is a data plane issue only, with no control plane exposure. The vulnerability affects various versions of NGINX Plus, NGINX Gateway Fabric, NGINX Ingress Controller, and F5 WAF.
Defensive priority
Medium-priority defensive actions are recommended due to the potential for remote unauthenticated attackers to cause a restart of the NGINX worker process.
Recommended defensive actions
- Inventory and version checks for NGINX Plus deployments using the MQTT filter module
- Apply vendor patches or updates to affected versions
- Implement compensating controls to detect and prevent exploitation attempts
- Monitor NGINX worker process restarts and system logs for suspicious activity
- Consider disabling the MQTT filter module if not required
Evidence notes
Evidence from official sources indicates that NGINX Plus is vulnerable to a heap buffer over-read when using the MQTT filter module. The vulnerability allows unauthenticated attackers to cause a restart of the NGINX worker process. Affected versions and configurations are detailed in the CVE and NVD records. Defenders should verify NGINX Plus deployments, review vendor advisories, and monitor for suspicious activity.
Official resources
-
CVE-2026-60065 CVE record
CVE.org
-
CVE-2026-60065 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T15:16:47.320Z and has not been modified since then.