# NGINX flaws enable RCE across major versions

Published: 2026-06-18 · Severity: high
Canonical: https://vorant.io/reports/88b19bb1-fa3e-5f8f-8e8c-b3b9e6464f9f/nginx-flaws-enable-rce-across-major-versions

> Multiple vulnerabilities in NGINX Open Source, NGINX Plus, and NGINX Gateway Fabric allow remote code execution, denial of service, and data confidentiality breaches.

CERT-FR has published an advisory detailing multiple security vulnerabilities affecting widely-deployed NGINX products. The flaws impact NGINX Open Source versions 1.30.x and 1.31.x, NGINX Plus versions R33 through R37, and NGINX Gateway Fabric versions 1.3.0 through 2.6.3. The vulnerabilities enable attackers to execute arbitrary code remotely, trigger denial-of-service conditions, compromise data confidentiality, and compromise data integrity.

F5 and NGINX have released patches to address the issues, identified as CVE-2026-42055, CVE-2026-42530, and CVE-2026-48142. Organizations running affected versions should prioritize applying the available updates: NGINX Open Source 1.30.3 and 1.31.2, NGINX Plus R36 P6 and 37.0.2.1, and NGINX Gateway Fabric 2.6.4.

Given NGINX's widespread deployment as a web server and reverse proxy across enterprise environments, the remote code execution capability represents a significant attack surface. Organizations should review their NGINX deployments and apply vendor patches according to the referenced security bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42055, CVE-2026-42530, CVE-2026-48142

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0775/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/88b19bb1-fa3e-5f8f-8e8c-b3b9e6464f9f/nginx-flaws-enable-rce-across-major-versions.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
