The critical NGINX vulnerability , CVE-2026-42945, is being actively exploited by cybercriminals just days after its public disclosure. The vulnerability affects both NGINX Plus and NGINX Open, has a CVSS score of 9.2 , and can cause worker process crashes or even remote code execution. The fact that the vulnerability targets one of the most widely used web servers in the world makes the situation particularly worrisome for the international cybersecurity community.

According to cybersecurity firm VulnCheck , CVE-2026-42945 is a heap buffer overflow vulnerability in the ngx_http_rewrite_module that affects NGINX versions from 0.6.27 to 1.30.0.
The vulnerability was introduced into the code in 2008 and remained hidden for nearly 18 years, according to depthfirst. This long period of latency highlights the importance of regular security audits and automated vulnerability scans on critical infrastructure systems.
See also: NGINX Rift: Critical 18-year-old vulnerability allows RCE without authentication
NGINX: What can an attacker do with the vulnerability?
As previously stated, successful exploitation of the vulnerability allows an unauthenticated attacker to cause worker processes to crash or execute code via malicious HTTP requests.
However, code execution is only possible on systems where Address Space Layout Randomization (ASLR) has been disabled. The absence of ASLR on production systems is rare, but it still exists in legacy installations or environments with special performance requirements that have disabled security mitigations.
Security researcher Kevin Beaumont pointed out that, in addition to disabled ASLR, the vulnerability relies on a specific NGINX and requires an attacker to know or discover that configuration in order to achieve RCE (remote code execution). This reliance on specific conditions somewhat reduces the risk, but does not eliminate it entirely, especially in environments where attackers have time to investigate their targets' configurations.

AlmaLinux maintainers also explained that converting a heap overflow into reliable code execution is not easy in the default system configuration. On NGINX systems with ASLR enabled, it is not expected to be easy to produce a general, reliable exploit. However, advanced attackers with specialized knowledge of heap manipulation and memory layout exploitation may be able to circumvent these limitations .
See also: Apache ActiveMQ CVE-2026-34197: Critical vulnerability in the KEV catalog
As the maintainers pointed out, “not easy” does not mean “impossible,” and a DoS attack that causes workers to crash is in itself enough to be considered urgent.
The vulnerability is triggered when certain configurations include rewrite, if , or set directives with unnamed PCRE captures such as $1 or $2. These configurations are particularly common in complex web applications that use URL rewriting for SEO purposes or API routing.
The latest findings from VulnCheck indicate that cybercriminals have begun targeting the vulnerability, with exploitation attempts being detected in their honeypot networks. The nature of the offensive activity and the ultimate goals remain unknown at this time. The speed with which the vulnerability has gone from a theoretical threat to an active exploit highlights the increasing maturity of threat actors and the need for a prompt response from security teams.
See also: GitHub fixed critical RCE vulnerability in less than 6 hours

Practical protection tips and immediate measures
To protect against the NGINX vulnerability, system administrators should immediately apply the available fixes. F5 has released patches for the affected versions, and it is recommended to upgrade to NGINX 1.30.1 or later for the Open Source version. In addition, administrators should check their configurations for the presence of dangerous rewrite patterns and implement temporary workarounds if an immediate upgrade is not possible.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The CVE-2026-42945 vulnerability poses a significant risk due to the widespread use of NGINX as a web server, reverse proxy, and load balancer on millions of servers worldwide. The rapid exploitation of this vulnerability reminds businesses of the importance of proactive cybersecurity and promptly applying security patches.
source: thehackernews.com
