Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
At 06:34am on 2 June 2026, an attacker logged on to a customer's network.
At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account.
F5 has issued out-of-band security updates to address critical vulnerabilities in NGINX, including CVE-2026-42530, a use-after-free flaw in the ngx_http_v3_module. This vulnerability allows remote, unauthenticated attackers to exploit NGINX’s HTTP/3 implementation, potentially causing worker-process restarts and denial of service.
F5 has issued urgent security updates to address CVE-2026-42530, a critical use-after-free vulnerability in NGINX’s ngx_http_v3_module. This flaw allows remote, unauthenticated attackers to trigger worker-process restarts and denial of service (DoS) by exploiting a specially crafted HTTP/3 session.
F5 addressed a critical NGINX vulnerability (CVE-2026-42530) in the HTTP/3 module that can cause worker-process restarts and denial of service. In environments with weakened ASLR, the flaw may also lead to arbitrary code execution, making patching urgent for internet-facing deployments.
A Technical Walkthrough of How Vidar Defeats.