logo

Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack

ID: 48c766d8-a4c1-5416-b5ba-699b6c012449

STIX ID: report--48c766d8-a4c1-5416-b5ba-699b6c012449

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ashish Khaitan

...
...

Security researchers disclosed CVE-2026-42945 (“NGINX Rift”), a critical memory-corruption flaw in NGINX Open Source and NGINX Plus (and some F5 products) that can be triggered by crafted HTTP requests using certain rewrite directive patterns; exploitation attempts were observed soon after public disclosure, and vendors have released patches and mitigations including updated packages and recommendations to replace unnamed regex captures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.