Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3145 articles · 183352 vulns · 37/41 feeds (7d)
← Back to list
6.4
CVE-2026-60062EXPLOITEDPATCHED
f5 · nginx agent

NGINX Agent Vulnerability

Description

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx agent2.0.0, 2.22.0, 2.17.1

References

  • https://my.f5.com/manage/s/article/K000161971(vendor-advisory, patch)

Related News (1 articles)

Tier C
VulDB19d ago
CVE-2026-60062 | F5 NGINX Agent/NGINX Instance Manager Configuration information disclosure
→ No new info (linked only)
CVSS 3.16.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
3.0.02.47.02.22.2*
CWECWE-22
PublishedJul 15, 2026
Last enriched19d agov2
Trending Score3
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 141
HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 15
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 5
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 4
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 19d ago
v2Tier C19d ago

Updated description with new details, changed severity to HIGH, marked as actively exploited, and noted that no exploit is available.

descriptionseverityactivelyExploited
via VulDB
v119d ago

Initial creation