Hackers Exploiting Critical NGINX RCE Vulnerability to Crash Servers and Gain Access
An 18 Year Old NGINX Vulnerability Is Now Being Exploited in the Wild As an independent cybersecurity blogger and part time penetration tester, vulnerabilities affecting internet infrastructure software are among the most dangerous security events organizations can face. The latest example involves a newly exploited flaw in: NGINX Open Source NGINX Plus F5 NGINX products tracked as: CVE-2026-42945 Also known as NGINX Rift Researchers confirmed attackers are already exploiting the vulnerability in the wild only days after public disclosure. The flaw carries a: CVSS score of 9.2 Critical Potential for unauthenticated remote code execution Ability to crash NGINX worker processes remotely What makes this especially alarming is that the vulnerability reportedly existed undetected since: 2008 Across nearly two decades of NGINX deployments worldwide. What Happened: Attackers Began Exploiting CVE-2026-42945 Researchers from depthfirst and F5 discl...