Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-50107EXPLOITEDPATCHED
f5 · nginx gateway fabric

NGINX Gateway Fabric vulnerability

Description

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these CRDs may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx gateway fabric2.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
nginxnginx pluscert_advisory90%
nginxnginxcert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000161785(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories66d ago
[NEU] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek66d ago
F5 Patches Critical, High-Severity NGINX Vulnerabilities
→ No new info (linked only)
Tier C
VulDB67d ago
CVE-2026-50107 | F5 NGINX Gateway Fabric up to 2.6.3 NGINX Configuration Generator injection (K000161785)
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.6.4
CWECWE-74
PublishedJun 17, 2026
Last enriched66d agov3
Trending Score0
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple Vulnerabilities in F5 Products
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
HIGHCVE-2026-42530EXP
NGINX Open-Source ngx_http_v3_module vulnerability
HIGHCVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: severity, affectedVersions, activelyExploited
Jun 18, 2026
Updated: cweIds
Jun 18, 2026
Actively Exploited
Jun 18, 2026
Patch Available
Jun 18, 2026

Version History

v3
Last enriched 66d ago
v3Tier D66d ago

Updated severity to HIGH, CVSS score to 9.2, added new CWE IDs, and marked exploit as available.

cweIds
via SecurityWeek
v2Tier C67d ago

Updated severity to CRITICAL, affected versions to include 2.6.3, and noted that no exploit exists.

severityaffectedVersionsactivelyExploited
via VulDB
v167d ago

Initial creation