Known vulnerabilities in NGINX Plus
Vendor:
F5 Networks
Software:
NGINX Plus
Software CPE:
cpe:2.3:a:f5_networks:nginx_plus:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
28
Public exploits:
3
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
37.0.6.1
37.1.1.1
37.0.6
37.0.5
37.0.4
37.1.1
37.1.0
37.0.3.1
R36 P7
R36 P6
37.0.2.1
R32 P7
R36 P5
37.0.1.1
37.0.0
R32 P6
R36 P4
R32 P5
R35 P2
R36 P3
R34 P1
R34
R32 P4
R35 P1
R36 P2
R36 P1
R36
R32 P3
R33 P3
R34 P2
R35
R28
R29
R32 P2
R33 P2
R33 P1
R33
R31 P3
R32 P1
R31 P2
R32
R31 P1
R30 P2
R30 P1
R31
R30
Vulnerabilities (28)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU150109 - Heap-based Buffer Overflow CVE-2026-90439 |
CWE-122 | Medium | 37.0.6.1, 37.1.1.1 | 15.09.2026 |
SB2026091584 |
||
| #VU137847 - Heap-based Buffer Overflow CVE-2026-42533 |
CWE-122 | High | R36 P7, 37.0.3.1 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 14 more |
||
| #VU137846 - Use of Uninitialized Resource CVE-2026-60005 |
CWE-908 | High | R36 P7, 37.0.3.1 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 11 more |
||
| #VU137845 - Use After Free CVE-2026-56434 |
CWE-416 | Medium | R36 P7, 37.0.3.1 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 11 more |
||
| #VU134864 - Out-of-bounds read CVE-2026-48142 |
CWE-125 | Medium | R36 P6, 37.0.2.1 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 10 more |
||
| #VU134861 - Heap-based Buffer Overflow CVE-2026-42055 |
CWE-122 | High | R36 P6, 37.0.2.1 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 13 more |
||
| #VU132220 - Heap-based Buffer Overflow CVE-2026-9256 |
CWE-122 | Critical | R32 P7, R36 P5, 37.0.1.1 | 25.05.2026 |
SB2026052502 SB2026052504 SB2026052505 and 12 more |
||
| #VU131379 - Use After Free CVE-2026-40701 |
CWE-416 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |
||
| #VU131378 - Authentication Bypass by Spoofing CVE-2026-40460 |
CWE-290 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 4 more |
||
| #VU131377 - Heap-based Buffer Overflow CVE-2026-42945 |
CWE-122 | Critical | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 27 more |
||
| #VU131375 - Uncontrolled Memory Allocation CVE-2026-42946 |
CWE-789 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 14 more |
||
| #VU131374 - Out-of-bounds read CVE-2026-42934 |
CWE-125 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |
||
| #VU124482 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-28753 |
CWE-93 | Medium | R32 P5, R35 P2, R36 P3 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026041117 and 4 more |
||
| #VU124478 - Heap-based Buffer Overflow CVE-2026-27654 |
CWE-122 | Medium | R32 P5, R35 P2, R36 P3 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026033174 and 17 more |
||
| #VU124475 - Out-of-bounds write CVE-2026-32647 |
CWE-787 | High | R32 P5, R35 P2, R36 P3 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 17 more |
||
| #VU124473 - NULL Pointer Dereference CVE-2026-27651 |
CWE-476 | Medium | R32 P5, R35 P2, R36 P3 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 17 more |
||
| #VU124470 - Incorrect Authorization CVE-2026-28755 |
CWE-863 | Medium | R32 P5, R35 P2, R36 P3 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026081734 |
||
| #VU122335 - Acceptance of Extraneous Untrusted Data With Trusted Data CVE-2026-1642 |
CWE-349 | Medium | R32 P4, R35 P1, R36 P2 | 05.02.2026 |
SB2026020501 SB2026020505 SB2026020511 and 22 more |
||
| #VU114082 - Out-of-bounds read CVE-2025-53859 |
CWE-125 | Low | R32 P3, R33 P3, R34 P2, R35 | 14.08.2025 |
SB2025081427 SB2025082564 SB2025082961 and 12 more |
||
| #VU103686 - Improper Authentication CVE-2025-23419 |
CWE-287 | Low | R32 P2, R33 P2 | 06.02.2025 |
SB2025020653 SB2025020670 SB2025020671 and 17 more |
Showing elements 1 - 20 out of 28