Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
6.4
CVE-2026-60062EXPLOITEDPATCHED
f5 · nginx agent

NGINX Agent Vulnerability

Description

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx agent2.0.0, 2.22.0, 2.17.1

References

  • https://my.f5.com/manage/s/article/K000161971(vendor-advisory, patch)

Related News (1 articles)

Tier C
VulDB39d ago
CVE-2026-60062 | F5 NGINX Agent/NGINX Instance Manager Configuration information disclosure
→ No new info (linked only)
CVSS 3.16.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
3.0.02.47.02.22.2*
CWECWE-22
PublishedJul 15, 2026
Last enriched39d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple Vulnerabilities in F5 Products
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
HIGHCVE-2026-42530EXP
NGINX Open-Source ngx_http_v3_module vulnerability
HIGHCVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
HIGHCVE-2026-50107EXP
NGINX Gateway Fabric vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 39d ago
v2Tier C39d ago

Updated description with new details, changed severity to HIGH, marked as actively exploited, and noted that no exploit is available.

descriptionseverityactivelyExploited
via VulDB
v139d ago

Initial creation