VORANT. Threat Intelligence Sign in Get the full feed

F5 NGINX Open Source patches DoS flaw

routine vulnerability technology

CERT-FR advisory details a NGINX Open Source vulnerability allowing remote denial of service and data integrity compromise, fixed in versions 1.31.6 and 1.30.5.

CERT-FR published an advisory on September 2026 covering a vulnerability in F5's NGINX Open Source software, tracked as CVE-2026-90439. The flaw affects NGINX Open Source versions 1.31.x prior to 1.31.6, as well as versions up to 1.30.5, and allows a remote attacker to trigger a denial-of-service condition and compromise the integrity of data. The advisory does not indicate that the vulnerability is currently being exploited in the wild.

Defenders running affected NGINX Open Source deployments should consult F5's security bulletin (K000162604, published 15 September 2026) and apply the vendor's patches promptly. No proof-of-concept or exploitation details are included in this advisory; organizations should prioritize patching based on their exposure of internet-facing NGINX instances and internal risk assessment.

Mentioned in this report

Vulnerabilities CVE-2026-90439

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1182

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free