logo

Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945

ID: d7f41ae7-6c30-5d3b-9b42-9265bde440e6

STIX ID: report--d7f41ae7-6c30-5d3b-9b42-9265bde440e6

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Pierluigi Paganini

...
...

A critical heap-buffer-overflow vulnerability (CVE-2026-42945, “NGINX Rift”) in ngx_http_rewrite_module affecting NGINX Plus and Open Source is being actively exploited; the flaw is triggered by specific rewrite patterns involving unnamed PCRE groups and a question mark in replacements, leading to a deterministic heap overflow. Public analysis and a PoC show exploitation potential but note that real-world remote code execution is unlikely without a specific vulnerable NGINX configuration and ASLR being disabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.