Millions at Risk as NGINX Zero-Day RCE Flaw Sees Real-World Exploitation

1 min read
Source: CyberSecurityNews
Millions at Risk as NGINX Zero-Day RCE Flaw Sees Real-World Exploitation
Photo: CyberSecurityNews
TL;DR Summary

Security researchers say CVE-2026-42945, a heap buffer overflow in NGINX Open Source and NGINX Plus, is being actively exploited in the wild. The flaw can crash NGINX worker processes via crafted requests, with remote code execution possible only if ASLR is disabled and a specific rewrite configuration is present; despite ASLR generally enabled, estimates show up to 5.7 million internet-facing servers may be affected. Organizations should patch promptly, ensure ASLR remains enabled, and audit rewrite rules to mitigate risk while threat actors rapidly scan for vulnerable systems.

Share this article

Reading Insights

Total Reads

0

Unique Readers

15

Time Saved

57 min

vs 58 min read

Condensed

99%

11,46287 words

Want the full story? Read the original article

Read on CyberSecurityNews