Known vulnerabilities in NGINX Plus R32 P5
Vendor:
F5 Networks
Software:
NGINX Plus
Version:
R32 P5
Software CPE:
cpe:2.3:a:f5_networks:nginx_plus:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
7
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134864 - Out-of-bounds read CVE-2026-48142 |
CWE-125 | Medium | R36 P6, 37.0.2.1 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 10 more |
||
| #VU132220 - Heap-based Buffer Overflow CVE-2026-9256 |
CWE-122 | Critical | R32 P7, R36 P5, 37.0.1.1 | 25.05.2026 |
SB2026052502 SB2026052504 SB2026052505 and 12 more |
||
| #VU131379 - Use After Free CVE-2026-40701 |
CWE-416 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |
||
| #VU131378 - Authentication Bypass by Spoofing CVE-2026-40460 |
CWE-290 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 4 more |
||
| #VU131377 - Heap-based Buffer Overflow CVE-2026-42945 |
CWE-122 | Critical | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 26 more |
||
| #VU131375 - Uncontrolled Memory Allocation CVE-2026-42946 |
CWE-789 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 14 more |
||
| #VU131374 - Out-of-bounds read CVE-2026-42934 |
CWE-125 | Medium | R32 P6, R36 P4 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |