June 21, 2026
- F5 shipped out-of-band patches for two critical NGINX Open Source flaws, including CVE-2026-42530 ("nginx-quicburst," CVSS 9.2) — a use-after-free in the HTTP/3 QUIC module (
ngx_http_v3_module) allowing remote unauthenticated RCE. It's only the third NGINX bug since 2014 to earn a "major" rating; affects 1.31 with QUIC enabled, and a technical write-up with ASLR bypass is promised July 18 (The Hacker News, Nebula Security).
· Vulnerabilities & Exploits
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- F5 shipped out-of-band fixes for two critical NGINX Open Source RCE flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module triggerable by a remote unauthenticated attacker. No exploitation reported yet, but the QUIC path warrants prompt patching. The Hacker News, CVE
· Vulnerabilities & Exploits
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- F5 shipped out-of-band patches for two critical NGINX Open Source flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module (
ngx_http_v3_module) that a remote unauthenticated attacker can trigger for code execution (The Hacker News, BleepingComputer).
· Vulnerabilities & Exploits
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk