HIGHVulnerability
Global

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

·Source: The Hacker News

Updated:

Executive Summary

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the

Analysis

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the

Indicators of Compromise (1)

CVE (1)
CVE-2026-42945
Source Attribution

Originally published by The Hacker News on May 17, 2026.

Related Threats