Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are co…
Nginx Gateway Fabric
1.30.4 / 2.6.7+
MEDIUM 6.4
CVE-2026-60062
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur…
Nginx Agent
2.22.2 / 2.46.7+
MEDIUM 5.3
CVE-2026-60065
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at…
Nginx Gateway Fabric
2.6.7 / 5.5.3+
HIGH 7.5
CVE-2026-59762
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Impac…
Big Ip Next Cloud Native Network Functions
1.4.3 / 1.7.18+
HIGH 8.3
CVE-2026-55723
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the …
Nginx Ingress Controller
5.5.2+
MEDIUM 6.5
CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (…
Nginx Gateway Fabric
2.6.7 / 5.5.3+
MEDIUM 6.5
CVE-2026-52865
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I…
Nginx Ingress Controller
5.5.2+
HIGH 8.1
CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege…
Nginx Gateway Fabric
2.6.7 / 5.5.3+
HIGH 8.1
CVE-2026-50107
When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configu…
Nginx Gateway Fabric
2.6.4+
MEDIUM 6.5
CVE-2026-32682
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources c…
Nginx Gateway Fabric
2.6.4+
HIGH 8.1
CVE-2026-42055
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists whe…
Dos
37.0.2.1+
HIGH 8.1
CVE-2026-42530
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote …
Nginx Gateway Fabric
1.31.2 / 2.6.4+
MEDIUM 6.5
CVE-2026-11311
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator comp…
Nginx Gateway Fabric
2.6.4+
HIGH 8.1
CVE-2026-9256EPSS 10%
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses …
Nginx Open Source
1.30.2 / 2.6.2+
CRITICAL 9.8
CVE-2026-8711
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,…
Njs
0.9.9+
HIGH 8.1
CVE-2026-42945EPSS 66%
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is …
Dos
after 5.12.1
HIGH 7.4
CVE-2026-42946
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read o…
Dos
after 5.12.1
MEDIUM 6.5
CVE-2026-42937
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These…
Big Ip Access Policy Manager
after 17.5.1.4
HIGH 8.7
CVE-2026-42924
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-42930
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BI…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-42920
When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Managemen…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 6.7
CVE-2026-42919
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successf…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 5.8
CVE-2026-42926
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be abl…
Nginx Gateway Fabric
after 5.4.2
MEDIUM 6.5
CVE-2026-42781
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tr…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-42406
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can …
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-42409
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests c…
Big Ip Next Cloud Native Network Functions
after 17.5.1
MEDIUM 6.5
CVE-2026-41959
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.8
CVE-2026-41957
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.
Note: Softw…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-41953
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify c…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-41956
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to termi…
Big Ip Access Policy Manager
after 17.5.1