CVE-2026-40701General(f5 / dos)

LOWCVSS 6.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch f5 dos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

2.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-15); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

1 version affected across 7 products

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-05-15: 3Mentions · 2026-05-16: 1Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-15: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 105-1505-1605-2005-2105-2205-23
Signal classification3 categories
General
450.0%
Disclosure
337.5%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-153
Disclosure2Patch1
2026-05-161
Disclosure1
2026-05-201
General1
2026-05-211
General1
2026-05-221
General1
2026-05-231
General1
Full discourse8 posts
  • Israel@f1tym1
    Disclosure

    CVE-2026-40701 | F5 NGINX Plus/NGINX Open Source Configuration ngx_http_ssl_module use after free (K000161021 / WID-SEC-2026-1527) https://ift.tt/EJ1S3g4 A vulnerability categorized as critical has been discovered in F5 NGINX Plus and NGINX Open Source. Affected is the functio…

    Post summary

    A critical use‑after‑free vulnerability (CVE‑2026‑40701) was announced for F5 NGINX Plus and NGINX Open Source, with basic technical details highlighted.

    0100069
    974 followersView on X
  • Matthew Rosenquist@Matt_Rosenquist
    Disclosure

    More chained vulns are being discovered because of AI tools NGINX Rift is the latest Remote Code Execution (RCE), that combines 4 vulns CVE-2026-42945 Critical (9.2) CVE-2026-42946 High (8.3) CVE-2026-40701 Medium (6.3) CVE-2026-42934 Medium (6.3) https://api.cyfluencer.com/s/nginx-rift-chain-remote-code-execution-rce-discovered-leveraging-18-year-old-vulnerabilities-1cb958a3-27380/1

    Post summary

    The post announces a new NGINX Rift RCE chain that combines four CVEs, providing severity scores but no details on active exploitation or patches.

    00010123
    1.2K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 54% of vulnerabilities from past week, CVE-2026-40701 has 30 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet notes that CVE-2026-40701 has numerous online articles but offers no technical details, exploit information, or patch guidance.

    0000054
    71 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 45% of vulnerabilities from past week, CVE-2026-40701 has 30 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes a high article count for CVE-2026-40701 but provides no specific exploit details, patches, or technical information.

    0000056
    71 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 36% of vulnerabilities from past week, CVE-2026-40701 has 30 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE-2026-40701 has received many articles but does not provide technical, exploit, or mitigation details.

    0000059
    71 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 27% of vulnerabilities from past week, CVE-2026-40701 has 30 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE‑2026‑40701 has many published articles and links to a CVE listing site, but it provides no technical, PoC, exploit, or mitigation details.

    0000071
    71 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-40701 | F5 NGINX Plus/NGINX Open Source Configuration ngx_http_ssl_module use after free (K000161021 / Nessus ID 314992) https://ift.tt/EJ1S3g4 A vulnerability categorized as critical has been discovered in F5 NGINX Plus and NGINX Open Source. Affected is the function…

    Post summary

    A critical use‑after‑free vulnerability (CVE-2026-40701) was identified in F5 NGINX Plus and NGINX Open Source, affecting the ngx_http_ssl_module. No exploit, PoC, or patch details are provided.

    0000046
    974 followersView on X
  • Vũ Trụ Số@vutruso
    Patch

    Nginx 1.31.0 Security Update - 6 CVEs Fixed CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution) CVE-2026-42926 - HTTP/2 request injection via proxy_set_body CVE-2026-42946 CVE-2026-42934 CVE-2026-40460 CVE-2026-40701 https://t.co/eRNItKkZIM

    Post summary

    Nginx releases a security update for version 1.31.0 that fixes six CVEs, including a heap buffer overflow that could enable code execution and an HTTP/2 request injection vulnerability.

    0000085
    35 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.8.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5waf-nginx-

Explore more