These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The ngx_http_slice_module module in NGINX Plus and NGINX Open Source is vulnerable to uninitialized memory access. This vulnerability allows unauthenticated attackers to send requests that may cause memory disclosure or NGINX worker process restarts when the slice directive and unnamed regex captures are configured or during background cache updates. The module is not enabled by default and requires the - [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T15:16:47.320Z and has not been modified since then. The NVD entry is currently Analyzed. NGINX Plus MQTT filter module (ngx_stream_mqtt_filter) 7 allows unauthenticated attackers to cause a heap buffer over-read leading to a worker process restart. This data plane issue affects various NGINX Plus [truncated]
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. This vulnerability can be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. The CVE record was published on 2026-07-15T15:16:47.190Z and has not been modified since then. Administr [truncated]
CVE-2026-59762 is a vulnerability in BIG-IP systems where undisclosed requests can cause an increase in memory resource utilization when an HTTP/2 profile is configured on a virtual server. This can lead to a degradation of service and potentially a denial-of-service (DoS). The issue is a data plane issue only, with no control plane exposure. A remote, unauthenticated attacker can exploit this vulnerabili [truncated]
The ngx_http_ssi_module module in NGINX Plus and NGINX Open Source is vulnerable to a use-after-free attack when Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. An unauthenticated attacker with man-in-the-middle (MITM) ability may exploit this vulnerability to cause a use-after-free in the NGINX worker process, potentially leading to limited modification of memor [truncated]
CVE-2026-52865 is a denial-of-service (DoS) vulnerability in the F5 Nginx Ingress Controller. An authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate, resulting in a persistent crash loop. This control plane issue has a CVSS score of 7.1 and is classified as HIGH severity. Users of F5 Nginx Ingre [truncated]
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests, potentially causing a heap buffer overflow in the NGINX worker process leading to a restart or code ex [truncated]
CVE-2026-50107 is an injection vulnerability in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these CRDs may craft values tha [truncated]
An authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. This vulnerability exists in NGINX Gateway Fabric when configured using GRPCRoutes. The attacker must have permission to create or modify GRPCRoute resources to exploit this vulnerability.
A vulnerability was found in NGINX Open Source and NGINX Plus. The ngx_http_charset_module module can cause a heap buffer over-read when serving or proxying content through a location block with specific charset configurations. This issue allows remote, unauthenticated attackers to potentially disclose memory or cause a restart. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Users of [truncated]
A critical vulnerability CVE-2026-42530 was found in NGINX Open Source's HTTP/3 QUIC module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Attackers can also execute code on systems with Addres [truncated]
CVE-2026-42055 is a medium-severity vulnerability in ngx_http_proxy_v2_module and ngx_http_grpc_module, addressed in EasyApache 4 25.67 security updates. This release updates ea-nginx from v1.31.1 to v1.31.2. The updates fix buffer overflow issues in the affected modules. Users of cPanel/WHM with EasyApache 4 should verify and apply the updated packages to prevent potential buffer overflow attacks.
CVE-2026-11311 is an injection vulnerability in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from Custom Resource Definitions can be rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary N [truncated]
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules of NGINX that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.
A heap buffer over-read vulnerability exists in NGINX Plus and NGINX Open Source due to improper handling of charset, source_charset, and charset_map directives with proxy_pass and disabled buffering. This allows unauthenticated attackers to cause a limited disclosure of memory or a restart. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Affected product deployments should assess and [truncated]
CVE-2026-42930 is a high-severity vulnerability in F5 BIG-IP systems that allows authenticated attackers with the 'Administrator' role to bypass Appliance mode restrictions. This issue affects multiple BIG-IP products and versions, including those in the 16.1, 17.1, and 17.5 branches. The vulnerability has a CVSS score of 8.5, indicating high severity. Organizations should be aware of this issue and take [truncated]
PatchSiren debrief for CVE-2026-42926, a MEDIUM severity vulnerability in NGINX Open Source. The vulnerability allows an attacker to inject frame headers and payload bytes to the upstream peer when NGINX Open Source is configured to proxy HTTP/2 traffic. This can occur when proxy_http_version is set to 2 and proxy_set_body is used. Users of NGINX Open Source configured to proxy HTTP/2 traffic should be aw [truncated]
CVE-2026-42924 is a high-severity vulnerability in F5 BIG-IP products that allows authenticated attackers with the Resource Administrator or Administrator role to create SNMP configuration objects through iControl SOAP, resulting in privilege escalation. The vulnerability has a CVSS score of 8.5 and is considered HIGH. Multiple versions of BIG-IP products are affected, including 16.1.0 through 16.1.6, 17. [truncated]
CVE-2026-42919 is a high-severity vulnerability in F5 BIG-IP systems that allows authenticated attackers with administrative access to escalate privileges. A successful exploit may allow the attacker to cross a security boundary. The vulnerability affects multiple versions of BIG-IP products, including BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, and others. This vulnerability is partic [truncated]
CVE-2026-42406 is a high-severity vulnerability in F5 BIG-IP and BIG-IQ systems. A highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects to run arbitrary commands. This issue affects multiple F5 products across various versions. The CVSS score is 8.5, indicating a high level of severity.
CVE-2026-41959 is a HIGH-severity vulnerability affecting F5 BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and BIG-IP iControl REST. An authenticated attacker may exploit this vulnerability to view the network status of destination systems. The vulnerability has a CVSS score of 7.1 and was published on May 13, 2026. Multiple versions of BIG-IP and BIG-IQ are affected, including those th [truncated]
CVE-2026-41957 is an authenticated remote code execution vulnerability in the BIG-IP and BIG-IQ Configuration utility. Defenders should assess exposure given the high CVSS score of 8.7 and the wide range of affected products. This vulnerability was made public on May 13, 2026, and last modified on June 23, 2026. The priority posture for defenders is to review and apply mitigations, especially given the hi [truncated]
CVE-2026-41956 is a high-severity vulnerability in F5 BIG-IP Traffic Management Microkernel. When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects multiple F5 BIG-IP products and versions. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7, indicating a hi [truncated]
CVE-2026-41954 is a sensitive information disclosure vulnerability in undisclosed iControl REST endpoint and TMOS Shell (tmsh) command of F5 products. An authenticated attacker with resource administrator role privileges may be able to view sensitive information. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. F5 has provided mitigation guidance in article K32950402.
CVE-2026-41953 is a high-severity vulnerability in BIG-IP systems that allows a highly privileged, authenticated attacker to modify configuration objects, resulting in privilege escalation. The vulnerability has a CVSS score of 8.5 and is considered HIGH. F5 has provided mitigation guidance for this issue. Software versions that have reached End of Technical Support (EoTS) are not evaluated. The CVE was p [truncated]
CVE-2026-41227 is a vulnerability in F5 BIG-IP Advanced Web Application Firewall that can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. This issue affects multiple F5 products, including BIG-IP Advanced Web Application Firewall, BIG-IP Application Security Manager, and BIG-IP DDoS Hybrid Defender. The vulnerability has a CVSS score of 8. [truncated]
CVE-2026-41225 is a vulnerability in F5 iControl REST that allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that enable running arbitrary commands. This issue affects multiple F5 products across various versions. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. F5 has provided mitigation guidance for this issue.
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. This vulnerability, tracked as CVE-2026-40703, has a CVSS score of 5.3 and is considered medium severity. The vulnerability affects various versions of BIG-IP products, including BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, and others. Software versions that have reached End of [truncated]
CVE-2026-40699 is a high-severity vulnerability in F5 BIG-IP Access Policy Manager. A low-privileged authenticated attacker may access undisclosed sensitive information. The vulnerability has a CVSS score of 7.1 and is considered HIGH. F5 has provided mitigation guidance. Software versions that have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40698 is a high-severity vulnerability in BIG-IP and BIG-IQ systems that allows a highly privileged, authenticated attacker with at least the Resource Administrator role to create SNMP configuration objects through iControl REST or the TMOS shell (tmsh), resulting in privilege escalation. This vulnerability has a CVSS score of 8.5 and is considered HIGH. The vulnerability affects multiple version [truncated]
CVE-2026-40631 is a HIGH severity vulnerability in F5 BIG-IP products. An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP, resulting in privilege escalation. This issue affects multiple F5 BIG-IP products across various versions. Software versions that have reached End of Technical Support (EoTS) are not evaluated. F5 has [truncated]
CVE-2026-40629 is a HIGH severity vulnerability in F5 BIG-IP products. When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. This issue affects multiple F5 BIG-IP products across various versions. The vulnerability has a CVSS score of 8.7. F5 has provided mitigation guidance.
A high-severity vulnerability was discovered in BIG-IP, a product by F5 Networks. The vulnerability, tracked as CVE-2026-40618, can cause the Traffic Management Microkernel (TMM) to terminate when an SSL profile is configured on a virtual server without Intel QuickAssist Technology (QAT) or when the database variable crypto.hwacceleration is set to disabled. This can lead to a denial of service, making th [truncated]
CVE-2026-40462 is a high-severity vulnerability in F5 products, allowing authenticated attackers to view sensitive information. The vulnerability exists in iControl REST and TMOS shell (tmsh) undisclosed command. Software versions that have reached End of Technical Support (EoTS) are not evaluated. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.1, indicating a high severi [truncated]
CVE-2026-40460 is a medium-severity vulnerability affecting NGINX Plus and NGINX Open Source when configured to use the HTTP/3 QUIC module. An attacker may exploit this vulnerability to spoof their source IP address, potentially bypassing authorization or rate limiting. The vulnerability has a CVSS score of 6.9 and is considered medium severity. Software versions that have reached End of Technical Support [truncated]
CVE-2026-40435 is a vulnerability in F5 BIG-IP products where IP-based access restrictions for httpd do not cover all endpoints. This may allow connections from blocked addresses. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Software versions that have reached End of Technical Support (EoTS) are not evaluated. The CVE was published on May 13, 2026, and modified on June 29, 2026.
A vulnerability in BIG-IP APM access policy can cause the apmd process to terminate when undisclosed traffic is received. This HIGH-severity vulnerability has a CVSS score of 8.7. The affected products are BIG-IP Access Policy Manager versions 16.1.0 to 16.1.6, 17.1.0 to 17.1.3, and 17.5.0 to 17.5.1. Software versions that have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command in BIG-IP DNS, which allows an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. This vulnerability has a CVSS score of 8.5 [truncated]
CVE-2026-40060 is a HIGH-severity vulnerability (CVSS Score: 8.7) affecting BIG-IP Advanced WAF or ASM security policy. When a security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. The vulnerability was published on May 13, 2026, and modified on June 29, 2026. F5 is the affected vendor. Software versions that have reached End of Technical Support (E [truncated]
CVE-2026-39459 is a highly severe vulnerability with a CVSS score of 8.6. A highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands via iControl REST and TMOS Shell (tmsh). This vulnerability affects multiple F5 BIG-IP products across various versions. Software versions that have reached End of Technical Support (EoTS) [truncated]
CVE-2026-34019 is a medium-severity vulnerability affecting F5 BIG-IP products. When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets. This can lead to the configured routing protocol failing over. The vulnerability has a CVSS score of 6.3 and is considered m [truncated]
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. This issue affects multiple versions of BIG-IP and BIG-IQ systems. Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in the gtm_add and bigip_add iControl REST commands of BIG-IP DNS. When BIG-IP DNS is provisioned, these commands return the ssh-password parameter in cleartext in the iControl REST response. The cleartext password is also logged in the audit log. A highly privileged, authenticated attacker with access to the audit log could view sensitive information. This issue affects multiple ve [truncated]
CVE-2026-20916 is a highly severe vulnerability affecting F5's BIG-IQ Centralized Management. An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. F5 has provided mitigation guidance for this issue. Users should review and apply the necessary patches o [truncated]
CVE-2025-53521 is a known-exploited F5 BIG-IP stack-based buffer overflow vulnerability listed by CISA in the Known Exploited Vulnerabilities catalog on 2026-03-27, with a remediation due date of 2026-03-30. Based on the supplied official sources, the safest assumption is that affected BIG-IP deployments should be treated as urgent priority, especially if internet-facing. Follow F5’s mitigation guidance, [truncated]
CVE-2026-32647 is a high-severity vulnerability affecting NGINX Open Source and NGINX Plus. The vulnerability is located in the ngx_http_mp4_module module and can be exploited using a specially crafted MP4 file, potentially leading to buffer over-read or over-write, causing NGINX worker memory termination or code execution. The vulnerability has a CVSS score of 8.5 and is considered HIGH. This issue affec [truncated]
CVE-2026-27784 is a vulnerability in the 32-bit implementation of NGINX Open Source's ngx_http_mp4_module module. This issue may allow an attacker to over-read or over-write NGINX worker memory, resulting in its termination, using a specially crafted MP4 file. The vulnerability only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the con [truncated]
CVE-2026-27654 is a high-severity vulnerability in NGINX Open Source and NGINX Plus that could allow an attacker to trigger a buffer overflow, potentially disrupting the NGINX worker process or modifying file names outside the document root. The vulnerability affects configurations using the DAV module's MOVE or COPY methods, prefix locations, and alias directives. The impact is somewhat constrained due t [truncated]
CVE-2023-46748 is a SQL injection vulnerability in the F5 BIG-IP Configuration Utility that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-31. Because CISA lists it as actively exploited, affected environments should be treated as urgent remediation items. The supplied official sources confirm the KEV status and the vendor product name, but do not provide affected versions or CVSS da [truncated]
CVE-2023-46747 affects the F5 BIG-IP Configuration Utility and is described as an authentication bypass vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-31, and the KEV record notes known ransomware campaign use. Because the source corpus identifies this as a known exploited issue, defenders should treat it as urgent and follow vendor guidance immediately; if mitigati [truncated]