NGINX Rift CVE-2026-42945 Is an 18-Year-Old Bug That Hands Attackers Your Web Server
A heap buffer overflow in NGINX ngx_http_rewrite_module has been hiding in the codebase since 2008. CVE-2026-42945 (CVSS 9.2) lets unauthenticated attackers hijack any unpatched NGINX instance. With NGINX powering over 30% of the internet, patch immediately.