F5 Security Updates – 21 June 2026

F5 has released security updates to address several vulnerabilities affecting multiple F5 products.

The addressed vulnerabilities could allow the attacker to conduct denial of service attacks, obtain sensitive information, or execute arbitrary code on the affected system.

Sample of the addressed vulnerabilities:

1. NGINX Use-After-Free Vulnerability (CVE-2026-42530):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

2. NGINX Gateway Fabric Data Disclosure Vulnerability (CVE-2026-11311):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information

Sample of the affected products:

  • NGINX Gateway Fabric.
  • F5 DoS for NGINX.
  • NGINX Open Source.
  • NGINX Instance Manager.
  • F5 WAF for NGINX.
Vulnerabilities
  • CVE-2026-42530
  • CVE-2026-42055
  • CVE-2026-11311
  • CVE-2026-50107
  • CVE-2026-48142
  • CVE-2026-32682
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References