CRITICAL ⚡ MUST-KNOW
NGINX CVE-2026-42945: Heap Buffer Overflow Exploited in the Wild, RCE Risk
A heap buffer overflow in NGINX’s ngx_http_rewrite_module (CVE-2026-42945, CVSS 9.2) is being actively exploited days after public disclosure. Affected versions span NGINX Plus and NGINX Open from 0.6.27 through 1.30.0. Successful exploitation can crash worker processes and may enable remote code execution. VulnCheck confirmed in-the-wild activity; security firm depthfirst published supporting analysis. Patch immediately — NGINX serves a significant share of global web traffic, making this a high-value target for threat actors.