Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3155 articles · 183371 vulns · 37/41 feeds (7d)
← Back to list
3.7
CVE-2026-60065EXPLOITEDPATCHED
f5 · nginx plus

NGINX Plus ngx_stream_mqtt_filter_module vulnerability

Description

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx plus37.0.0.1, R36, R33

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
nginxnginx pluscert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000162101(vendor-advisory, patch)

Related News (2 articles)

Tier B
BSI Advisories18d ago
[NEU] [hoch] NGINX NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB19d ago
CVE-2026-60065 | F5 NGINX Plus prior 37.0.3.1/R36 P7 MQTT Filter heap-based overflow
→ No new info (linked only)
CVSS 3.13.7 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
37.0.3.1R36 P7*
CWECWE-125
PublishedJul 15, 2026
Last enriched19d agov2
Trending Score4
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 141
HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 15
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 5
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 3
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 19d ago
v2Tier C19d ago

Updated description with new technical details, changed severity to HIGH, and marked as actively exploited.

descriptionseverityactivelyExploited
via VulDB
v119d ago

Initial creation