CVE-2026-42945
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità · 134 giorni fa
La pubblicazione del public PoC ha ridotto la finestra per la patch da giorni a ore. Un bug di NGINX corretto di recente viene già colpito in the wild, quindi questa non è più una disclosure che puoi rimandare al prossimo ciclo di manutenzione. Il livello edge è il bersaglio e, in alcune distribuzioni, un semplice crash è sufficiente a mandare in tilt i servizi.
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Patch Microsoft: CBL-Mariner Releases.
4 fonti che coprono questa storia
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security
A critical NGINX vulnerability (CVE-2026-42945) that was disclosed last week is being exploited by attackers, according to VulnCheck.
Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
CVE-2026-42945 is exploited after disclosure, impacting NGINX 0.6.27–1.30.0 and enabling crashes or RCE.
PoC Code Published for Critical NGINX Vulnerability
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
18-year-old NGINX vulnerability allows DoS, potential RCE
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.
F5 Patches Over 50 Vulnerabilities
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
Part of the PlainSec briefing for 2026-05-16