---
格式版本: 2
标题: "F5 Patches Multiple NGINX, BIG-IP Vulnerabilities - SecurityWeek"
原文链接: "https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/"
发布日期: "2026-07-15"
发布时间校准状态: "found"
发布时间来源: "llm:strict_original_body"
发布时间证据: "div class=zox-byline-wrap: July 15, 2026"
发布时间校准原因: "位于标题下方作者/来源区域的日期，符合文章发布时间特征。"
发布时间校准置信度: "1"
发布时间候选数量: 16
发布时间严格候选数量: 6
发布时间原页读取状态: "原页面来自已抓取 HTML"
发布时间未找到原因: "候选日期无效或 LLM 未确认"
发布时间校准时间: "2026-07-19T22:37:25+08:00"
发现时间: "2026-07-19T17:46:07+08:00"
入库时间: "2026-07-19T15:01:02.938Z"
来源平台: "Tavily（AgentKey）"
搜索渠道: "tavily_web"
搜索词: "Nvlink"
匹配关键词:
  []
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "AgentKey Scrape"
清洗工具: "AgentKey Markdown + LLM 正文裁剪"
原始附件:
  []
AI优质: "否"
AI打分: 21
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "文章主题为F5修复NGINX和BIG-IP安全漏洞，属于网络安全领域，与超节点、AI Rack、机柜级AI基础设施、高速互连、供电散热等核心主题完全无关。"
AI质检模型: "qwen3.6-plus"
AI质检时间: "2026-07-19T23:01:02+08:00"
AI主题相关性: 0
AI来源权威性: 8
AI新颖性: 5
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 8
图片摘要:
  - "✗ ./assets/img-d0d77d3c.jpg | photo | 品牌Logo，无实质技术信息"
采集批次: "2026年7月19日17点45分46秒"
采集批次ID: "20260719-174546-694"
去重键: "https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities"
---

**F5 on Wednesday announced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP.**

The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process.

“A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map’s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions,” F5 explains.

An attacker can exploit the security defect without authentication, but only under conditions they cannot control. On systems with Address Space Layout Randomization (ASLR) disabled, the attacker can achieve code execution.

F5’s patches also resolve several high-severity NGINX bugs, including weaknesses in the *ngx\_http\_slice\_module* module and the *ngx\_http\_ssi\_module* module that can be exploited without authentication.

Successful exploitation of the flaws allows attackers to leak memory contents, restart the NGINX worker process, or cause a use-after-free in the NGINX worker process to modify memory or restart the process.

Advertisement. Scroll to continue reading.

Two high-severity vulnerabilities addressed in NGINX Ingress Controller could allow authenticated attackers to inject arbitrary NGINX configuration directives to delete files and disable services, or create or modify Ingress or TransportServer resources to cause a denial-of-service (DoS) condition.

F5 also resolved a high-severity security defect in BIG-IP that could be exploited by remote, unauthenticated attackers to increase memory resource utilization when an HTTP/2 profile is configured on a virtual server, causing a DoS condition.

F5 makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found in the company’s out-of-band [security notification](https://my.f5.com/manage/s/article/K000161837).

**Related:** [Trend Micro, Tanium, ESET, and Tenable Patch Severe Product Vulnerabilities](https://www.securityweek.com/trend-micro-tanium-eset-and-tenable-patch-severe-product-vulnerabilities/)

**Related:** [Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow](https://www.securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow/)

**Related:** [ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell](https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-rockwell/)

**Related:** [Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates](https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates/)

![图片](./assets/img-9d1360de.jpg)

![图片](./assets/img-477a0722.jpg)Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. [(Tod Beardsley)](https://www.securityweek.com/contributors/tod-beardsley/)

![图片](./assets/img-9d3342cc.jpg)Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. [(Steve Durbin)](https://www.securityweek.com/contributors/stevedurbin/)

![图片](./assets/img-d277cc37.jpg)As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. [(Matias Madou)](https://www.securityweek.com/contributors/matias-madou/)

![图片](./assets/img-59f4d936.jpg)From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. [(Joshua Goldfarb)](https://www.securityweek.com/contributors/joshua-goldfarb/)

![图片](./assets/img-b4eaf711.jpg)As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. [(Danelle Au)](https://www.securityweek.com/contributors/danelle-au/)
