NGINX Rift CVE-2026-42945 - 18-year-old rewrite-module flaw enables unauthenticated RCE on millions of web servers
An 18-year-old vulnerability in the NGINX rewrite module, codenamed NGINX Rift (CVE-2026-42945, CVSS 9.2), lets unauthenticated attackers run remote code with a single HTTP request. Affects every NGINX version from 0.6.27 through 1.30.0 and NGINX Plus R32-R36. Patches are now ava
An 18-year-old vulnerability in the NGINX rewrite module, codenamed NGINX Rift (CVE-2026-42945, CVSS 9.2), lets unauthenticated attackers run remote code with a single HTTP request. Affects every NGINX version from 0.6.27 through 1.30.0 and NGINX Plus R32-R36. Patches are now available in 1.30.1 and 1.31.0.
Published on
TikTokYouTubeBlueskyThreadsFacebookInstagram