Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY16 SECURITY RECORDS

F5

NGINX Plus

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-90439 15 Sep 2026 NGINX Plus: 37.1.0.1 < 37.1.1.2, 37.0.0.1 < 37.0.6.2; NGINX Open Source: 1.29.2 < 1.31.6, 1.30.4 < 1.30.5 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-60005 15 Jul 2026 37.0.0.1 < 37.0.3.1; R36 < R36 P7; R33 < *; 1.31.2 < 1.31.3; 1.15.8 < 1.30.4 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-60065 15 Jul 2026 37.0.0.1 < 37.0.3.1; R36 < R36 P7; R33 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56434 15 Jul 2026 37.0.0.1 < 37.0.3.1; R36 < R36 P7; R33 < *; 1.31.2 < 1.31.3; 0.8.11 < 1.30.4 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-42533 15 Jul 2026 37.0.0.1 < 37.0.3.1; R36 < R36 P7; R33 < *; 1.31.2 < 1.31.3; 0.9.6 < 1.30.4 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-9256 22 May 2026 37.0 < 37.0.1.1; R36 < R36 P5; R32 < R32 P7; 1.31.0 < 1.31.1; 1.30.0 < 1.30.2; 0.1.17 ≤ 0.9.7 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-40460 13 May 2026 R36 < R36 P4; R32 < R32 P6; 1.26.0 < 1.30.1 R37 < *; 1.31.0 < * Update reference ↗
CVE-2026-42946 13 May 2026 R36 < R36 P4; R32 < R32 P6; 0.8.42 < 1.30.1 R37 < *; 1.31.0 < * Update reference ↗
CVE-2026-42934 13 May 2026 R36 < R36 P4; R32 < R32 P6; 0.3.50 < 1.30.1 R37 < *; 1.31.0 < * Update reference ↗
CVE-2026-42945 13 May 2026 NGINX Plus: R36 < R36 P4, R32 < R32 P6; NGINX Open Source: 0.6.27 < 1.30.1 NGINX Plus: R37 < *; NGINX Open Source: 1.31.0 < * Update reference ↗
CVE-2026-40701 13 May 2026 R36 < R36 P4; R32 < R32 P6; 1.19.0 < 1.30.1 R37 < *; 1.31.0 < * Update reference ↗
CVE-2025-53859 13 Aug 2025 R34 < R34 P2; R33 < R33 P3; R32 < R32 P3; R31 < *; R30 < *; 0.7 < 1.29.1 R35 Update reference ↗
CVE-2024-39792 14 Aug 2024 R30 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-24990 14 Feb 2024 R31 < R31 P1; R30 < R30 P2; 1.25.0 < 1.25.4 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2024-24989 14 Feb 2024 R31 < R31 P1; 1.25.3 < 1.25.4 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2022-41743 19 Oct 2022 R27 < R27-p1; R1 < R26-p1 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.