<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Http3 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/http3/</link><description>Recent content in Http3 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 18 Jun 2026 17:32:14 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/http3/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical NGINX RCE Flaws Patched – CVE-2026-42530</title><link>https://zxcloudsecurity.co.uk/posts/f5-nginx-critical-rce-cve-2026-42530-http3-use-after-free/</link><pubDate>Thu, 18 Jun 2026 17:32:14 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/f5-nginx-critical-rce-cve-2026-42530-http3-use-after-free/</guid><description>F5 patches two critical NGINX Open Source RCE vulnerabilities (CVE-2026-42530) exploitable by unauthenticated remote attackers via HTTP/3. Patch immediatel</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html">The Hacker News</a></p>
<hr>
<p>F5 has patched two critical vulnerabilities in NGINX Open Source, both of which could allow a remote, unauthenticated attacker to execute arbitrary code on affected systems. The flaws reside in the HTTP/3 module and carry a CVSS v4 score of 9.2, indicating high exploitability with no authentication required. NGINX is one of the world&rsquo;s most widely deployed web servers and reverse proxies, making the blast radius of these vulnerabilities significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Prioritise patching NGINX Open Source instances immediately, particularly any internet-facing deployments with HTTP/3 (QUIC) enabled — consider disabling HTTP/3 as a temporary mitigation if patching cannot be completed rapidly. Audit Kubernetes ingress controllers, API gateways, and load balancers that bundle NGINX, as these are commonly overlooked in patch cycles.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html">F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution</a></p>
]]></content:encoded></item></channel></rss>