A critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42945 (CVSS 9.2), is now being actively exploited in the wild just days after public disclosure. The flaw affects NGINX versions 0.6.27 through 1.30.0 and resides in the ngx_http_rewrite_module — a component that has been part of the NGINX codebase since 2008.

Successful exploitation allows an unauthenticated attacker to crash NGINX worker processes with crafted HTTP requests, and in specific configurations where Address Space Layout Randomization (ASLR) is disabled, full remote code execution is achievable. VulnCheck has confirmed exploitation attempts against its honeypot networks, though the specific threat actors and end goals remain unclear.

AlmaLinux maintainers noted that while turning the heap overflow into reliable RCE is non-trivial on systems with ASLR enabled, the worker-crash denial-of-service vector alone is serious enough to warrant urgent patching. F5 has released fixes that administrators should apply immediately.

Source

The Hacker News — NGINX CVE-2026-42945 Exploited in the Wild

Commentary

This is a significant vulnerability given NGINX’s massive footprint — it powers roughly a third of all websites on the internet. The 18-year-old code surface being exploited is a stark reminder that legacy components in widely-deployed infrastructure carry compounding risk over time.

The silver lining is that the RCE path requires ASLR to be disabled, which limits the blast radius on modern Linux systems. But the DoS vector is trivially exploitable and could be weaponized at scale against any NGINX deployment using the rewrite module. If you run NGINX in any capacity, patch now — don’t wait for a more convenient window.

By Allan