• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-42533: pre-auth remote code execution in F5 NGINX Plus

Remote attackers can trigger a heap buffer overflow in NGINX Plus and NGINX Open Source that may cause a crash or, in some environments, allow code execution. CVE-2026-42533 affects multiple branches: NGINX Plus 37.0.0.1 through before 37.0.3.1, NGINX Plus R36 before R36 P7, NGINX Plus R33, and Open Source ranges 0.9.6 through before 1.30.4 and 1.31.2 through before 1.31.3. Exploitation requires sending specially crafted HTTP requests; no authentication is required under the reported conditions.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.1HIGH
EPSS
0.00894
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so apply vendor fixes or mitigations immediately; the presence of public exploit code makes internet-facing NGINX instances high priority to update.

What is CVE-2026-42533?

Remote attackers can trigger a heap buffer overflow in NGINX Plus and NGINX Open Source that may cause a crash or, in some environments, allow code execution. CVE-2026-42533 affects multiple branches: NGINX Plus 37.0.0.1 through before 37.0.3.1, NGINX Plus R36 before R36 P7, NGINX Plus R33, and Open Source ranges 0.9.6 through before 1.30.4 and 1.31.2 through before 1.31.3. Exploitation requires sending specially crafted HTTP requests; no authentication is required under the reported conditions. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of F5 NGINX Plus are affected?

BRANCHAFFECTEDFIXED
NGINX Plus 37.x37.0.0.1 – before 37.0.3.137.0.3.1
NGINX PlusR36 – before R36 P7R36 P7
NGINX PlusR33
NGINX Open Source 1.x1.31.2 – before 1.31.31.31.3
NGINX Open Source 1.x0.9.6 – before 1.30.41.30.4

Is CVE-2026-42533 being exploited?

Public exploit code is available.

How to fix CVE-2026-42533

  1. Upgrade NGINX Plus 37.x to 37.0.3.1 or later.
  2. Upgrade NGINX Plus R36 to R36 P7 or later; follow vendor guidance for R33 which has no listed fix.
  3. Upgrade NGINX Open Source to 1.31.3 or 1.30.4 where applicable.
  4. If you cannot patch immediately, restrict external access to affected servers, monitor NGINX worker crashes and abnormal requests, and follow vendor mitigation recommendations.

Frequently asked questions

Is CVE-2026-42533 being actively exploited?

Public exploit code is available for CVE-2026-42533, indicating a higher risk of active exploitation.

Which NGINX Plus versions are affected by CVE-2026-42533?

NGINX Plus versions affected include 37.0.0.1 through before 37.0.3.1, R36 before R36 P7, and R33 is listed as affected with no fixed release noted.

Is there a patch for CVE-2026-42533?

Patches are available: NGINX Plus 37.0.3.1, R36 P7, and NGINX Open Source 1.31.3 and 1.30.4 address the issue; R33 has no fixed version listed.

Does CVE-2026-42533 require authentication?

No authentication is required under the conditions described; the issue can be triggered by crafted HTTP requests.

References