A newly disclosed security flaw impacting NGINX Plus and NGINX
Open has come under active exploitation in the wild, days after its
public disclosure, according to VulnCheck. The vulnerability,
tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer
overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27
through 1.30.0. According to AI-native security company depthfirst,
the
Read more https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html

