<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2026-42533: Check Point WAF Managed NGINX Deployments Are Not Vulnerable in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280441#M426</link>
    <description>&lt;P&gt;New deployments might use 1.30.4, but I found we run&amp;nbsp;&lt;SPAN&gt;1.24.0-r16 which is on the affected list.&amp;nbsp;&lt;BR /&gt;But still our analysis found that the active&amp;nbsp;NGINX-config did &lt;STRONG&gt;not find any &amp;nbsp;regex-capture-variables and no volatile-maps.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Can you confirm that these versions are not vulnerable as well? Or do we need to redeploy?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2026 07:17:21 GMT</pubDate>
    <dc:creator>khatland</dc:creator>
    <dc:date>2026-07-30T07:17:21Z</dc:date>
    <item>
      <title>CVE-2026-42533: Check Point WAF Managed NGINX Deployments Are Not Vulnerable</title>
      <link>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280411#M424</link>
      <description>&lt;P&gt;F5 has disclosed &lt;STRONG&gt;CVE-2026-42533&lt;/STRONG&gt;, a security vulnerability affecting specific NGINX configurations that use the &lt;CODE&gt;map&lt;/CODE&gt; directive with regular expression matching under particular conditions. Successful exploitation could result in a denial-of-service (DoS) condition and, in certain environments, potentially lead to remote code execution.&lt;/P&gt;
&lt;P&gt;We would like to reassure our customers that &lt;STRONG&gt;Check Point WAF managed NGINX deployments are not vulnerable to CVE-2026-42533.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;Why Check Point WAF Customers Are Not Affected&lt;/H2&gt;
&lt;P&gt;Check Point WAF currently runs &lt;STRONG&gt;NGINX Open Source 1.30.4&lt;/STRONG&gt;, which is listed by NGINX as &lt;STRONG&gt;not vulnerable&lt;/STRONG&gt; to CVE-2026-42533.&lt;/P&gt;
&lt;P&gt;Additionally, the vulnerability requires a &lt;STRONG&gt;specific configuration pattern&lt;/STRONG&gt; involving the &lt;CODE&gt;map&lt;/CODE&gt; directive, regex matching, and the order in which regex capture variables are referenced. &lt;STRONG&gt;None of Check Point WAF managed deployment templates use this vulnerable configuration&lt;/STRONG&gt;, making the published attack vector &lt;STRONG&gt;not applicable&lt;/STRONG&gt; to our managed service.&lt;/P&gt;
&lt;H2&gt;Customer Impact&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;No action is required&lt;/STRONG&gt; for customers using &lt;STRONG&gt;Check Point WAF managed NGINX deployments&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;As part of our secure software development lifecycle, we continuously monitor newly disclosed vulnerabilities, evaluate their applicability to our managed platform, and ensure our managed deployments remain protected through timely software updates and secure-by-default configurations.&lt;/P&gt;
&lt;P&gt;Should additional guidance become necessary, we will communicate it through our standard customer notification channels.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 18:23:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280411#M424</guid>
      <dc:creator>Vani</dc:creator>
      <dc:date>2026-07-29T18:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-42533: Check Point WAF Managed NGINX Deployments Are Not Vulnerable</title>
      <link>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280441#M426</link>
      <description>&lt;P&gt;New deployments might use 1.30.4, but I found we run&amp;nbsp;&lt;SPAN&gt;1.24.0-r16 which is on the affected list.&amp;nbsp;&lt;BR /&gt;But still our analysis found that the active&amp;nbsp;NGINX-config did &lt;STRONG&gt;not find any &amp;nbsp;regex-capture-variables and no volatile-maps.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Can you confirm that these versions are not vulnerable as well? Or do we need to redeploy?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 07:17:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280441#M426</guid>
      <dc:creator>khatland</dc:creator>
      <dc:date>2026-07-30T07:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-42533: Check Point WAF Managed NGINX Deployments Are Not Vulnerable</title>
      <link>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280504#M427</link>
      <description>&lt;P&gt;Based on what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/117909"&gt;@Vani&lt;/a&gt;&amp;nbsp;said above, no, as we are not using a configuration that exposes the vulnerability.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 13:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/CVE-2026-42533-Check-Point-WAF-Managed-NGINX-Deployments-Are-Not/m-p/280504#M427</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-30T13:28:48Z</dc:date>
    </item>
  </channel>
</rss>

