logo

Hackers Exploit Critical NGINX RCE Vulnerability in the Wild

ID: 433e7d7e-c4fc-5941-8bb8-aec877bcd6b8

STIX ID: report--433e7d7e-c4fc-5941-8bb8-aec877bcd6b8

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Lucas Martin

...
...

**Critical NGINX heap overflow (CVE-2026-42945) — active exploitation and PoC in the wild; emergency patching required.** A rewrite-module heap buffer overflow in NGINX (affecting versions 0.6.27–1.30.0) permits attacker-controlled URI data to overflow worker heap buffers, enabling persistent DoS for most deployments and conditional remote code execution on systems with ASLR disabled; PoC and active exploitation were observed within days of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.