---
schema: 1
kind: vulnerability
title: CVE-2026-42945 NGINX Rift — in-the-wild exploitation confirmed by VulnCheck honeypots
headline: CVE-2026-42945 NGINX Rift — in-the-wild exploitation confirmed by VulnCheck honeypots
summary: "NGINX Rift CVE-2026-42945 — VulnCheck honeypot telemetry confirms in-the-wild exploitation as of 2026-05-17. The 18-year-old heap overflow in ngx_http_rewrite_module (versions 0.6.27 through 1.30.0) is now actively probed; patches are NGINX Open Source 1.30.1 / 1.31.0 and NGINX Plus R32 P6 / R36 P4 (The Hacker News, 2026-05-17; Security Affairs, 2026-05-14)."
discovered_at: "2026-05-18T05:00:02Z"
event_date: 2026-05-17
run_id: 2026-05-18-2eabc1cf
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - rce
  - dos
regions:
  - global
sectors:
  - public-sector
  - technology
entities: []
cves:
  - id: CVE-2026-42945
    cvss: "9.2"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html"
    publisher: "The Hacker News, 2026-05-17"
    role: primary
  - url: "https://my.f5.com/manage/s/article/K000161019"
    publisher: F5 PSIRT K000161019
    role: corroborating
  - url: "https://securityaffairs.com/192132/hacking/nginx-rift-an-18-year-old-flaw-in-the-worlds-most-deployed-web-server-just-came-to-light.html"
    publisher: "Security Affairs, 2026-05-14"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12575"
    publisher: "NCSC-CH Security Hub post #12575"
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-W21 weekly): VulnCheck honeypot telemetry confirmed active exploitation of CVE-2026-42945 on 2026-05-17, promoting the 18-year-old ngx_http_rewrite_module heap buffer overflow from PoC-public status (where it sat last week) to actively-exploited."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field); migration: update target unresolved (no originally-covered date in v2 body)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch NGINX 1.30.0 → 1.30.1 / 1.31.0 (open source) or NGINX Plus → R32 P6 / R36 P4 immediately on any internet-exposed instance.** VulnCheck honeypot telemetry confirmed in-the-wild exploitation of CVE-2026-42945 (\"NGINX Rift\") on 2026-05-17. Where same-day upgrade is not feasible, audit `nginx.conf` and included `*.conf` rewrite rules for unnamed PCRE captures (`$1`, `$2`) and convert to named captures as an interim mitigation per the F5 advisory."
migrated_from: briefs/2026-05-18.md
---

**UPDATE (originally covered 2026-W21 weekly):** [VulnCheck honeypot telemetry confirmed active exploitation of CVE-2026-42945 on 2026-05-17](https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html), promoting the 18-year-old `ngx_http_rewrite_module` heap buffer overflow from PoC-public status (where it sat last week) to actively-exploited. The flaw is reachable by an unauthenticated remote attacker via a single crafted HTTP request to any NGINX instance running a rewrite-rule configuration that uses unnamed PCRE captures (`$1`, `$2`); successful exploitation crashes the worker process (DoS reliable on ASLR-enabled hosts) and reaches RCE on hosts where ASLR is disabled.

Affected per [F5 PSIRT advisory K000161019](https://my.f5.com/manage/s/article/K000161019): NGINX Open Source 0.6.27 through 1.30.0 (every release since 2008) and NGINX Plus R32 through R36, plus F5 NGINX Instance Manager, NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, F5 WAF for NGINX, and NGINX App Protect DoS. Patches: NGINX Open Source 1.30.1 / 1.31.0; NGINX Plus R32 P6, R36 P4. Interim mitigation if immediate upgrade is not possible: convert unnamed PCRE captures in all rewrite directives to named captures (`(?P<name>...)` syntax). Detection-engineering anchors that follow from the flaw class (heap-overflow worker crash under specific rewrite-rule configurations) are NGINX worker-process crash events (SIGSEGV / SIGABRT and immediate respawn) in syslog / journald, correlated with inbound HTTP requests carrying unusually long or deeply-nested rewrite-rule input strings from the same source; defenders should validate these against their own rewrite-rule configuration before depending on them.
