Critical NGINX Vulnerability CVE-2026-42945 Exposes Servers to Remote Code Execution
ID: 13b27151-b9eb-5fdd-9218-1b02490a344b
STIX ID: report--13b27151-b9eb-5fdd-9218-1b02490a344b
Feed Name: ThreatCluster
Threat Score
**Critical NGINX Vulnerability (CVE-2026-42945) enables unauthenticated remote code execution via a heap-based buffer overflow in ngx_http_rewrite_module when certain unnamed PCRE captures and replacement strings are used; a PoC was published on 2026-05-13.** Immediate remediation is to upgrade to fixed NGINX releases or modify rewrite/if/set directives to avoid the vulnerable pattern.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
