logo

NGINX Rift attackers waste no time targeting exposed servers

ID: 2f1ddb3f-5e25-536e-afc8-a9c94c75b449

STIX ID: report--2f1ddb3f-5e25-536e-afc8-a9c94c75b449

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

Researchers disclosed an 18-year-old heap buffer overflow in NGINX's rewrite module ("NGINX Rift", CVE-2026-42945) that can crash worker processes and, on systems without ASLR or with specific rewrite configurations, potentially enable code execution; a public proof-of-concept and active exploitation attempts were observed days after disclosure, while scans show millions of potentially vulnerable NGINX instances, prompting urgent patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.