Skip to content
The Nexus
SECURITYMay 17 · 11:57 UTCTHE HACKER NEWS[email protected] (The Hacker News)

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A security flaw in NGINX Plus and NGINX Open is being actively exploited, causing worker crashes and possible remote code execution. The vulnerability, tracked as CVE-2026-42945, has a CVSS score of 9.2 and affects NGINX versions 0.6.27 through 1.30.0. The exploitation was reported by VulnCheck and depthfirst.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this