Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945
2026-05-18T08:51:41Z•8bb80681b1f9256cd00721f7d102abfccdc969b4bc4a30e0e119b5b7465d7af8
CVE-2026-41940CVE-2026-42897CVE-2026-42945Funnel BuilderKazuarKnown Exploited Vulnerability (KEV)Microsoft ExchangeNGINXOpenAIPwn2OwnTanStackTurlaWordPressactive exploitationbotnete-skimmerheap buffer overflowremote code execution (possible)supply chainvulnerabilityzero-day
What happened
Multiple high-impact vulnerabilities and active exploits were reported. A critical NGINX vulnerability (CVE-2026-42945, CVSS v4 9.2) in NGINX Open and NGINX Plus is being actively exploited to trigger heap buffer issues that can crash servers and may allow code execution. Microsoft Exchange zero-day CVE-2026-42897 (CVSS 8.1) was added to CISA’s KEV catalog and is also being actively exploited. Other notable incidents include active exploitation of CVE-2026-41940 (used by threat actor Mr_Rot13 to deploy backdoors), active attacks leveraging a critical Funnel Builder WordPress plugin flaw to sk
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8bb80681b1f9256cd00721f7d102abfccdc969b4bc4a30e0e119b5b7465d7af8
- Enrichment time
- 2026-05-18T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.