F5 NGINX Plus

5 known vulnerabilities in F5 NGINX Plus, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-90439 CVSS 6.9 medium NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL…
  • CVE-2026-42946 CVSS 8.3 high A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an…
  • CVE-2026-42945 CVSS 9.2 critical NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite…
  • CVE-2026-42934 CVSS 6.3 medium NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map…
  • CVE-2026-40701 CVSS 6.3 medium NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to…