NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
ID: 1794f3ff-9ad3-5e9d-bac0-a9a5824425f7
STIX ID: report--1794f3ff-9ad3-5e9d-bac0-a9a5824425f7
Feed Name: The Hacker News
A newly disclosed high-severity NGINX heap overflow (CVE-2026-42945, CVSS 9.2) and several critical openDCIM vulnerabilities (including CVE-2026-28515 and CVE-2026-28517, CVSS 9.3) are being actively targeted in the wild; NGINX exploitation can cause worker crashes and potentially RCE on systems with ASLR disabled while openDCIM flaws can be chained to spawn a reverse shell. VulnCheck observed exploitation attempts against honeypots and reports a likely actor (single Chinese IP) using an AI-driven scanning tool to find vulnerable installs and drop PHP web shells—administrators are advised to apply vendor fixes urgently.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
