F5 has issued critical security patches for NGINX Open Source to mitigate two severe vulnerabilities that could permit remote code execution on impacted systems. The most significant of these flaws is tracked as CVE-2026-42530, which carries a CVSS v4 score of 9.2. This vulnerability is identified as a use-after-free error residing within the ngx_http_v3_module of the software.
The vulnerability can be triggered by a remote, unauthenticated attacker, posing a substantial risk to environments running NGINX Open Source with the affected module enabled. Successful exploitation of this flaw could allow an attacker to execute arbitrary code without requiring prior access or credentials. F5 has not reported active exploitation in the wild but emphasizes the necessity of immediate patching to prevent potential compromise.
In addition to the primary remote code execution flaw, the security update addresses a second critical vulnerability categorized within the same release. Technical details indicate that the flaws are specific to certain configurations of NGINX Open Source, particularly those utilizing modern protocol modules that are susceptible to memory corruption issues during the handling of network requests.
For CIOs and IT directors, these updates represent a critical maintenance requirement for web infrastructure and application delivery controllers. Operations leaders should prioritize the deployment of these patches across all NGINX Open Source instances to maintain the integrity of their network perimeter and protect against unauthorized remote access.
