F5 Security Update – 24 May 2026

F5 has released a security update to address a vulnerability affecting F5 NGINX ngx_http_rewrite_module.

The addressed vulnerability could allow the remote attacker to perform denial of service (DoS) attacks on the NGINX system, or to possibly trigger code execution.

The addressed vulnerability:

NGINX ngx_http_rewrite_module Heap Buffer Overflow Vulnerability (CVE-2026-9256):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

The affected products:

  • NGINX Plus.
  • NGINX Open Source.
  • NGINX Instance Manager.
  • F5 WAF for NGINX.
  • NGINX App Protect WAF.
  • F5 DoS for NGINX.
  • NGINX App Protect DoS.
  • NGINX Gateway Fabric.
  • NGINX Ingress Controller.
Vulnerabilities

CVE-2026-9256

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References