logo

Critical NGINX Vulnerability CVE-2026-42945 Exposes Servers to Remote Code Execution

ID: 13b27151-b9eb-5fdd-9218-1b02490a344b

STIX ID: report--13b27151-b9eb-5fdd-9218-1b02490a344b

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

...
...

**Critical NGINX Vulnerability (CVE-2026-42945) enables unauthenticated remote code execution via a heap-based buffer overflow in ngx_http_rewrite_module when certain unnamed PCRE captures and replacement strings are used; a PoC was published on 2026-05-13.** Immediate remediation is to upgrade to fixed NGINX releases or modify rewrite/if/set directives to avoid the vulnerable pattern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.