CVE-2020-27730: F5 Nginx Controller
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
Affected products
- F5 Nginx Controller: from 2.0.0, up to and including 2.9.0; from 3.0.0, before 3.10.0 (fixed in 3.10.0); version 1.0.1 only
- Netapp Cloud Backup: affected versions not specified
Published 2020-12-11. Last modified 2026-06-17.