Back to Intel

Intel Node

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

mediumvulnerability2026-05-17T11:57:53+00:00source excerpt
vulnerabilitycve

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0.

Read Original Source