The active exploitation of CVE-2026-42945 in NGINX should be treated as an urgent infrastructure risk, especially for internet-facing web servers and reverse proxies. The flaw is a heap buffer overflow in ngx_http_rewrite_module, affecting NGINX versions 0.6.27 through 1.30.0, and can allow unauthenticated attackers to crash worker processes or potentially execute remote code through crafted HTTP requests.
While reliable RCE may depend on specific rewrite configurations and weaker memory protections such as ASLR being disabled, the confirmed exploitation attempts mean organizations should not wait for “perfect exploitability” before acting. Administrators should immediately apply vendor fixes, review rewrite rules, restrict exposed services, monitor for worker crashes, and check access logs for suspicious crafted requests. This is a fine reminder that “stable for 18 years” does not mean “safe”; sometimes it just means the bug aged quietly in production like a cursed antique.

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the
Source: NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE via The Hacker News — published 17 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.