Is Nginx 1.21.6 patched?
Current stable (1.31.2): 100/100
1.21.6 has 1 open critical-or-high vulnerability. Run 1.29.8 or later to clear it. See what 1.29.8 fixes →
Summary iPlain-English security status for Nginx 1.21.6, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Nginx 1.21.6 is part of the 1.21 release line. 1 known vulnerability affects it. The minimum safe version is 1.29.8 — upgrade to it or later to clear the open critical/high issues. The 1.21 line reached end-of-life on 2022-06-21, so it no longer receives security patches. The latest supported Nginx release is 1.31.2.
Known issues affecting 1.21.6
Exploited first, then by exploitation probability.
CVE-2026-49975 HIGH EPSS 1% → fixed in 1.29.8Other Nginx versions
Check another release line of Nginx.
Frequently asked
Is Nginx 1.21.6 patched?
Nginx 1.21.6 is end-of-life and no longer receives security patches. Move to 1.31.2.
What version should I upgrade Nginx 1.21.6 to?
Upgrade Nginx 1.21.6 to at least 1.29.8 to clear its 1 open critical-or-high vulnerability.
When does Nginx 1.21 reach end-of-life?
Nginx 1.21 reached end-of-life on 2022-06-21 and no longer receives security patches.
What is the latest version of Nginx?
The latest supported Nginx release is 1.31.2.
Is Nginx 1.21.6 still receiving security updates?
No — Nginx 1.21.6 is on the 1.21 line, which reached end-of-life on 2022-06-21 and no longer receives security updates. Upgrade to 1.31.2 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Nginx / F5's official advisory before you patch or upgrade — Nginx official site ↗