daily cyber × ai intelligence

index

tagged

[CVE-2026-42530]

3 editions · 3 items

June 21, 2026

  • F5 shipped out-of-band patches for two critical NGINX Open Source flaws, including CVE-2026-42530 ("nginx-quicburst," CVSS 9.2) — a use-after-free in the HTTP/3 QUIC module (ngx_http_v3_module) allowing remote unauthenticated RCE. It's only the third NGINX bug since 2014 to earn a "major" rating; affects 1.31 with QUIC enabled, and a technical write-up with ASLR bypass is promised July 18 (The Hacker News, Nebula Security). · Vulnerabilities & Exploits

in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog