F5 disclosed and patched a critical heap buffer overflow in nginx worker processes that can be triggered remotely by an unauthenticated attacker via crafted HTTP requests. The flaw can crash worker processes, causing denial of service, and may allow remote code execution in some configurations. Organizations running affected nginx or NGINX Plus versions should upgrade immediately.
Updated Jul 20, 2026