Critical NGINX vulnerability: CVE-2026-42945 under active attack
A buffer overflow flaw in NGINX is being actively exploited, putting global web servers at risk of potential remote attacks.

Security Alert: Active exploitation of CVE-2026-42945
The web server ecosystem is on high alert following confirmation that the CVE-2026-42945 vulnerability is being actively exploited in the wild. This flaw, assigned a CVSS score of 9.2, affects both NGINX Open Source and NGINX Plus, leaving a vast amount of critical global infrastructure exposed.
Technical details of the flaw
The flaw is identified as a heap buffer overflow located in the ngx_http_rewrite_module. According to reports from VulnCheck, the error impacts NGINX versions between 0.6.27 and 1.30.0. Successful exploitation not only causes worker processes to crash but also opens the door to remote code execution (RCE).
"The speed with which threat actors have begun using this exploit following its disclosure underscores the need for an immediate response from system administrators," cybersecurity experts warn.
Impact and mitigation measures
The risk of a successful hack is extremely high due to NGINX's ubiquity across the web. The ability for attackers to compromise these servers could lead to the deployment of ransomware or other forms of malicious persistence, similar to the tactics observed in recent incidents where Turla evoluciona Kazuar: el peligro de una botnet P2P persistente.
To protect your systems, it is recommended to:
- Update immediately: Move to an NGINX version that includes the corresponding security patch.
- Monitoring: Review error logs for unusual worker process restart attempts.
- Segmentation: Limit access to rewrite modules from untrusted networks.
This incident, added to recent events such as Pwn2Own Berlin 2026: Windows 11 and Edge suffer high-level hack, demonstrates that no layer of the technology stack is exempt from critical risks. Proactive patch management remains the most effective defense against modern malicious actors.
Conclusion
The NGINX security breach is a stark reminder of the fragility of infrastructure software. With active exploitation already underway, IT teams must prioritize updating their instances before the vulnerability is integrated into automated attack toolkits, exponentially increasing the danger to organizations.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...