CVE-2026-42945
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità ed exploit
La pubblicazione del public PoC ha ridotto la finestra per la patch da giorni a ore. Un bug di NGINX corretto di recente viene già colpito in the wild, quindi questa non è più una disclosure che puoi rimandare al prossimo ciclo di manutenzione. Il livello edge è il bersaglio e, in alcune distribuzioni, un semplice crash è sufficiente a mandare in tilt i servizi.
4 fonti · 18 mag
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Patch Microsoft: CBL-Mariner Releases.
Help Net Security
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security
A critical NGINX vulnerability (CVE-2026-42945) that was disclosed last week is being exploited by attackers, according to VulnCheck.
originaleSecurityWeek
Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
originaleThe Hacker News
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
CVE-2026-42945 is exploited after disclosure, impacting NGINX 0.6.27–1.30.0 and enabling crashes or RCE.
originalePart of the PlainSec briefing for 2026-05-15
Every edition of this story: Il public PoC trasforma NGINX in una superficie di attacco attiva