F5 disclosed multiple NGINX vulnerabilities across modules, with the most serious issues centered on the ngx_http_rewrite_module, including CVE-2026-42945 and CVE-2026-9256. The flaw dubbed NGINX Rift is a long-standing heap buffer overflow in the rewrite engine that can be triggered remotely through crafted HTTP requests, leading to worker crashes, repeated restarts, and denial of service; under some conditions, including disabled ASLR, remote code execution is possible. CSIRT.SK reported active exploitation of CVE-2026-42945 and said the bug affects both NGINX Open Source and F5/NGINX-related products, while F5 also published advisories for additional bugs in ngx_http_proxy_v2_module, ngx_http_charset_module, and ngx_http_js_module.
Independent analysis of the two rewrite-engine RCE bugs found that exploitation depends on specific rewrite patterns involving rewrite, if, set, positional captures, and question-mark handling in PCRE-based rules. Researchers behind the ngxray scanner reviewed 35,633 public NGINX configurations from GitHub and found only one confirmed real-world vulnerable configuration after triage, suggesting the bugs are severe but uncommon in exposed public configs. Defenders were urged to upgrade to fixed releases, including NGINX Open Source 1.30.1 or 1.31.0 and NGINX Plus R32 P6 or R36 P4, and to review or mitigate risky rewrite directives where patches were not yet available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Calif researchers published an analysis of CVE-2026-42945 and CVE-2026-9256, built the open-source static scanner ngxray, and scanned 35,633 public GitHub NGINX configurations. After triage, they found only one genuinely vulnerable real-world configuration, suggesting low prevalence of exploitable public configs despite the severity of the bugs.
F5 published a product advisory for CVE-2026-9256 affecting the NGINX ngx_http_rewrite_module. Later analysis grouped this flaw with CVE-2026-42945 as one of two critical NGINX rewrite-engine RCE issues.
F5 published a product advisory for CVE-2026-8711 affecting the NGINX ngx_http_js_module.
CSIRT.SK stated that exploitation of CVE-2026-42945 was confirmed active as of May 18, 2026. The notice also said the flaw could cause denial of service and potentially remote code execution if ASLR is disabled.
CSIRT.SK reported that exploitation of CVE-2026-42945 began in the wild on May 17, 2026. The activity involved the critical rewrite-module flaw known as NGINX Rift.
F5 published a product advisory for CVE-2026-42934 affecting the NGINX ngx_http_charset_module.
F5 published a product advisory for CVE-2026-42926 affecting the NGINX ngx_http_proxy_v2_module.
F5 published a product advisory for CVE-2026-42945 affecting the NGINX ngx_http_rewrite_module. The flaw was later described as the 18-year-old 'NGINX Rift' vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
blog.calif.io
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcecsirt.sk
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.