18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
- Posted on May 14, 2026
- By The Hacker News
- 0 Views
- 1 min read
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.