Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack
ID: 48c766d8-a4c1-5416-b5ba-699b6c012449
STIX ID: report--48c766d8-a4c1-5416-b5ba-699b6c012449
Feed Name: The Cyber Express
Threat Score
Security researchers disclosed CVE-2026-42945 (“NGINX Rift”), a critical memory-corruption flaw in NGINX Open Source and NGINX Plus (and some F5 products) that can be triggered by crafted HTTP requests using certain rewrite directive patterns; exploitation attempts were observed soon after public disclosure, and vendors have released patches and mitigations including updated packages and recommendations to replace unnamed regex captures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
