CVE-2026-42945
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Microsoft patch: CBL-Mariner Releases.
Vulnerabilities & Exploits
Public PoC publication has collapsed the patch window from days to hours. A recently fixed NGINX bug is already being hit in the wild, so this is no longer a disclosure you can defer to the next maintenance cycle. The edge tier is the target, and in some deployments a simple crash is enough to knock services over.
VulnCheck says it is seeing active exploitation of CVE-2026-42945 on canaries just days after the CVE was published and after Depthfirst released technical details and PoC code. The issue affects NGINX Open Source 0.6.27 through 1.30.0, NGINX Plus vR32 through R36, and F5 products that embed NGINX, including NGINX Ingress Controller and F5 WAF for NGINX.
The forward risk is broader than one vulnerable host. NGINX often sits in front of whole application stacks as a web server, reverse proxy, load balancer, or cache, so exploitation can become a control-plane problem for everything behind it. ASLR-disabled systems face code execution risk, and patching does not help any secrets or trust already exposed through the edge path.
4 sources · May 18
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Microsoft patch: CBL-Mariner Releases.
Help Net Security
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security
A critical NGINX vulnerability (CVE-2026-42945) that was disclosed last week is being exploited by attackers, according to VulnCheck.
originalSecurityWeek
Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
originalThe Hacker News
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
CVE-2026-42945 is exploited after disclosure, impacting NGINX 0.6.27–1.30.0 and enabling crashes or RCE.
originalPart of the PlainSec briefing for 2026-05-16
Every edition of this story: Public PoC Turns NGINX Into Active Attack Surface