Vulnerabilities · 119 days ago

Public PoC Turns NGINX Into Active Attack Surface

Public PoC publication has collapsed the patch window from days to hours. A recently fixed NGINX bug is already being hit in the wild, so this is no longer a disclosure you can defer to the next maintenance cycle. The edge tier is the target, and in some deployments a simple crash is enough to knock services over.

VulnCheck says it is seeing active exploitation of CVE-2026-42945 on canaries just days after the CVE was published and after Depthfirst released technical details and PoC code. The issue affects NGINX Open Source 0.6.27 through 1.30.0, NGINX Plus vR32 through R36, and F5 products that embed NGINX, including NGINX Ingress Controller and F5 WAF for NGINX.

The forward risk is broader than one vulnerable host. NGINX often sits in front of whole application stacks as a web server, reverse proxy, load balancer, or cache, so exploitation can become a control-plane problem for everything behind it. ASLR-disabled systems face code execution risk, and patching does not help any secrets or trust already exposed through the edge path.

CVE-2026-42945

NVD KEV

CVSS 8.1 HIGH: nGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

4 sources covering this story

Entities

Vendor digest: F5

Part of the PlainSec briefing for 2026-05-16

Editions

Related stories