Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3155 articles · 183371 vulns · 37/41 feeds (7d)
← Back to list
8.3
CVE-2026-55723EXPLOITEDPATCHED
f5 · nginx ingress controller

NGINX Ingress Controller vulnerability

Description

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx ingress controller5.0.0, 2026-lts-r1

References

  • https://my.f5.com/manage/s/article/K000161800(vendor-advisory, patch)

Related News (1 articles)

Tier C
VulDB19d ago
CVE-2026-55723 | F5 NGINX Ingress Controller up to 5.5.1 Configuration Generator injection
→ No new info (linked only)
CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
5.5.22026-lts-r3
CWECWE-76
PublishedJul 15, 2026
Last enriched19d agov2
Tags
CVE-2026-55723
Trending Score3
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 141
HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 15
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 5
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 4
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: severity, affectedVersions, activelyExploited, tags
Jul 15, 2026
Actively Exploited
Jul 16, 2026
Patch Available
Jul 16, 2026

Version History

v2
Last enriched 19d ago
v2Tier C19d ago

Updated severity to CRITICAL, added affected version 5.5.1, marked as actively exploited, and included new CVE tag.

severityaffectedVersionsactivelyExploitedtags
via VulDB
v119d ago

Initial creation