Vulnerabilities · 119 days ago
Public PoC Turns NGINX Into Active Attack Surface Public PoC publication has collapsed the patch window from days to hours. A recently fixed NGINX bug is already being hit in the wild, so this is no longer a disclosure you can defer to the next maintenance cycle. The edge tier is the target, and in some deployments a simple crash is enough to knock services over.
VulnCheck says it is seeing active exploitation of CVE-2026-42945 on canaries just days after the CVE was published and after Depthfirst released technical details and PoC code. The issue affects NGINX Open Source 0.6.27 through 1.30.0 , NGINX Plus vR32 through R36, and F5 products that embed NGINX, including NGINX Ingress Controller and F5 WAF for NGINX.
The forward risk is broader than one vulnerable host. NGINX often sits in front of whole application stacks as a web server, reverse proxy, load balancer, or cache, so exploitation can become a control-plane problem for everything behind it. ASLR-disabled systems face code execution risk, and patching does not help any secrets or trust already exposed through the edge path.
CVE-2026-42945 NVD KEV
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Microsoft patch: CBL-Mariner Releases.
Timeline Sources 4 sources covering this story
Help Net Security May 18
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security
A critical NGINX vulnerability (CVE-2026-42945) that was disclosed last week is being exploited by attackers, according to VulnCheck.
SecurityWeek May 18
Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
The Hacker News May 17
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
CVE-2026-42945 is exploited after disclosure, impacting NGINX 0.6.27–1.30.0 and enabling crashes or RCE.
SecurityWeek May 16
PoC Code Published for Critical NGINX Vulnerability
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
BleepingComputer May 14
18-year-old NGINX vulnerability allows DoS, potential RCE
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
The Hacker News May 14
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.
SecurityWeek May 14
F5 Patches Over 50 Vulnerabilities
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
Entities Vendor digest: F5
Part of the PlainSec briefing for 2026-05-16
Editions Related stories
Vulnerabilities · 119 days ago
Public PoC Turns NGINX Into Active Attack Surface Public PoC publication has collapsed the patch window from days to hours. A recently fixed NGINX bug is already being hit in the wild, so this is no longer a disclosure you can defer to the next maintenance cycle. The edge tier is the target, and in some deployments a simple crash is enough to knock services over.
VulnCheck says it is seeing active exploitation of CVE-2026-42945 on canaries just days after the CVE was published and after Depthfirst released technical details and PoC code. The issue affects NGINX Open Source 0.6.27 through 1.30.0 , NGINX Plus vR32 through R36, and F5 products that embed NGINX, including NGINX Ingress Controller and F5 WAF for NGINX.
The forward risk is broader than one vulnerable host. NGINX often sits in front of whole application stacks as a web server, reverse proxy, load balancer, or cache, so exploitation can become a control-plane problem for everything behind it. ASLR-disabled systems face code execution risk, and patching does not help any secrets or trust already exposed through the edge path.
CVE-2026-42945 NVD KEV
CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Microsoft patch: CBL-Mariner Releases.
Timeline Sources 4 sources covering this story
Help Net Security May 18
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security
A critical NGINX vulnerability (CVE-2026-42945) that was disclosed last week is being exploited by attackers, according to VulnCheck.
SecurityWeek May 18
Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
The Hacker News May 17
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
CVE-2026-42945 is exploited after disclosure, impacting NGINX 0.6.27–1.30.0 and enabling crashes or RCE.
SecurityWeek May 16
PoC Code Published for Critical NGINX Vulnerability
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
BleepingComputer May 14
18-year-old NGINX vulnerability allows DoS, potential RCE
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
The Hacker News May 14
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.
SecurityWeek May 14
F5 Patches Over 50 Vulnerabilities
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
Entities Vendor digest: F5
Part of the PlainSec briefing for 2026-05-16
Editions Related stories