NGINX Rift attackers waste no time targeting exposed servers
ID: 2f1ddb3f-5e25-536e-afc8-a9c94c75b449
STIX ID: report--2f1ddb3f-5e25-536e-afc8-a9c94c75b449
Feed Name: The Register (Security)
Threat Score
Researchers disclosed an 18-year-old heap buffer overflow in NGINX's rewrite module ("NGINX Rift", CVE-2026-42945) that can crash worker processes and, on systems without ASLR or with specific rewrite configurations, potentially enable code execution; a public proof-of-concept and active exploitation attempts were observed days after disclosure, while scans show millions of potentially vulnerable NGINX instances, prompting urgent patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
