AI Stories on SHORT INFO are generated & curated with AI
unverified 25 May, 12:11

NGINX Rift (CVE-2026-42945) - 18-year-old heap buffer overflow in NGINX rewrite module enables unauthenticated RCE; F5 patched May 13 2026, active exploitation reported

An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, codenamed NGINX Rift) lets unauthenticated attackers trigger memory corruption via crafted HTTP requests, with full remote code execution possible on systems where ASLR is weakened. F5 ($FFIV) shipped

An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, codenamed NGINX Rift) lets unauthenticated attackers trigger memory corruption via crafted HTTP requests, with full remote code execution possible on systems where ASLR is weakened. F5 ($FFIV) shipped patches under advisory K000161019 on May 13. Affected: NGINX Open Source through 1.30.0 and NGINX Plus R32 through R36. A proof of concept exploit chain is already public; active exploitation reported in the wild.

#cyber
Published on
YouTubeBlueskyThreadsFacebookInstagramTikTokX