logo

NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers

ID: 18c5f2bd-7362-592d-96eb-8e30daaa1184

STIX ID: report--18c5f2bd-7362-592d-96eb-8e30daaa1184

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

NGINX disclosed a critical vulnerability (CVE-2026-42945, 9.2) present since 2008 and patched in 1.30.1/1.31.0; threat actors are actively probing and some exploitation has been observed in honeypots. Successful RCE requires specific configuration conditions including ASLR disabled, but a DoS that crashes worker processes is easily executed; approximately 5.7 million unpatched instances remain exposed, so administrators are urged to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.