[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJsgylhT1JmhMslK-NXoVSwtO5a5OFF3DdFlVioBKaNo":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"b952ddd5-41c1-4b28-a4a3-bece4d3b9715","NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE","nginx-cve-2026-42945-exploited-in-the-wild-causing-worker-crashes-and-possible-r-7b6b6e","A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the","A critical heap buffer overflow vulnerability (CVE-2026-42945, CVSS 9.2) in NGINX's rewrite module affecting versions 0.6.27–1.30.0 is being actively exploited in the wild. The flaw can crash worker processes or enable remote code execution if ASLR is disabled and specific configurations are present. VulnCheck also reports active exploitation of three critical openDCIM vulnerabilities that can be chained for remote code execution via a Chinese IP using an AI vulnerability discovery tool.","NGINX CVE-2026-42945 heap buffer overflow exploited in wild; worker crashes and possible RCE.","NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Ravie LakshmananMay 17, 2026Server Security \u002F Vulnerability A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the vulnerability was introduced in 2008. Successful exploitation of the flaw can permit an unauthenticated attacker to crash worker processes or execute remote code with crafted HTTP requests. However, it bears noting that code execution is possible only on devices where Address Space Layout Randomization (ASLR), a safeguard against memory-based attacks, is turned off. \"It relies on a specific NGINX config to be vulnerable, and for an attacker to know or discover the config to exploit it,\" security researcher Kevin Beaumont said. \"To reach RCE [remote code execution], also ASLR needs to have been disabled on the box.\" In a similar assessment, AlmaLinux maintainers said: \"Turning the heap overflow into reliable code execution is not trivial in the default configuration, and on systems with ASLR enabled (which is the default on every supported AlmaLinux release), we do not expect a generic, reliable exploit to be easy to produce.\" \"That said, 'not easy' is not 'impossible,' and the worker-crash DoS is exploitable enough on its own that we recommend treating this as urgent,\" the maintainers added. The latest findings from VulnCheck show that threat actors have begun to weaponize the flaw, with exploitation attempts detected against its honeypot networks. The nature of the attack activity and the end goals are presently unknown. Users are advised to apply the latest fixes from F5 to secure their networks against active threats. Flaws in openDCIM Also Exploited The development comes as VulnCheck also revealed exploitation efforts targeting two critical flaws in openDCIM, an open-source application used for data center infrastructure management. The vulnerabilities, both rated 9.3 on the CVSS scoring system, are listed below - CVE-2026-28515 - A missing authorization vulnerability that could allow an authenticated user to access LDAP configuration functionality regardless of their assigned privileges. In Docker deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be reachable without credentials, allowing unauthorized modification of application configuration. CVE-2026-28517 - An operating system command injection vulnerability impacting the \"report_network_map.php\" component that processes a parameter called \"dot\" without sanitization and passes it directly to a shell command, resulting in arbitrary code execution. The two vulnerabilities were discovered alongside CVE-2026-28516 (CVSS score: 9.3), an SQL injection vulnerability in openDCIM, by VulnCheck security researcher Valentin Lobstein in February 2026. According to Lobstein, the three flaws can be chained to achieve remote code execution over five HTTP requests and spawn a reverse shell. \"The cluster of attacker activity we're observing so far originates from a single Chinese IP and uses what appears to be a customized implementation of AI vuln discovery tool Vulnhuntr to automatically check for vulnerable installations before dropping a PHP web shell,\" Caitlin Condon, vice president of security research at VulnCheck, said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Command Injection, cybersecurity, denial of service, exploitation, NGINX, remote code execution, VulnCheck, Vulnerability, Web Shell ⚡ Top Stories This Week Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday [Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI and More Packages cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation ⭐ Featured Resources [Webinar] Learn How to Handle Critical SOC Alerts With AI Support Identify Internal Attack Surfaces More Efficiently With a Free Assessment [eBook] Get the 3-Number SOC Diagnostic to Reduce Queue Risk [Guide] Stop Email Fraud Before It Turns Into Ransomware Damage","https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fnginx-cve-2026-42945-exploited-in-wild.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgdFtAiSRukEdQXVvEzXdQKy0O9SY7RCuqFLuAEIBe4rECuQuUS76qEXnxPuEcKIIFUysRNOGdBW2Mf2n1sh1W35aU0nCksWiW7v-20p1K7RhdPPDnxKh7kt_OmQaPrmtYPJ3larEwWr9iHeQMoRtlW767YpsXBFP5-5CQ2jTJUB_jWaMmt_29uLJvaGZE_\u002Fs1600\u002Fnginx.jpg","2026-05-17T11:57:53+00:00","2026-05-17T16:00:21.031472+00:00",9,[18,21,23,25,28,30],{"name":19,"type":20},"NGINX Plus","product",{"name":22,"type":20},"NGINX Open",{"name":24,"type":20},"openDCIM",{"name":26,"type":27},"F5","vendor",{"name":29,"type":27},"VulnCheck",{"name":31,"type":32},"Vulnhuntr","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59,62,65,68],{"type":56,"value":57,"context":58},"cve","CVE-2026-42945","Heap buffer overflow in NGINX ngx_http_rewrite_module, CVSS 9.2, affecting versions 0.6.27–1.30.0",{"type":56,"value":60,"context":61},"CVE-2026-28515","Missing authorization in openDCIM LDAP configuration, CVSS 9.3",{"type":56,"value":63,"context":64},"CVE-2026-28516","SQL injection in openDCIM, CVSS 9.3",{"type":56,"value":66,"context":67},"CVE-2026-28517","OS command injection in openDCIM report_network_map.php, CVSS 9.3",{"type":69,"value":70,"context":71},"malware","PHP web shell","Dropped by threat actor exploiting openDCIM vulnerabilities"]