Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945

2026-05-18T08:51:41Z8bb80681b1f9256cd00721f7d102abfccdc969b4bc4a30e0e119b5b7465d7af8
CVE-2026-41940CVE-2026-42897CVE-2026-42945Funnel BuilderKazuarKnown Exploited Vulnerability (KEV)Microsoft ExchangeNGINXOpenAIPwn2OwnTanStackTurlaWordPressactive exploitationbotnete-skimmerheap buffer overflowremote code execution (possible)supply chainvulnerabilityzero-day

What happened

Multiple high-impact vulnerabilities and active exploits were reported. A critical NGINX vulnerability (CVE-2026-42945, CVSS v4 9.2) in NGINX Open and NGINX Plus is being actively exploited to trigger heap buffer issues that can crash servers and may allow code execution. Microsoft Exchange zero-day CVE-2026-42897 (CVSS 8.1) was added to CISA’s KEV catalog and is also being actively exploited. Other notable incidents include active exploitation of CVE-2026-41940 (used by threat actor Mr_Rot13 to deploy backdoors), active attacks leveraging a critical Funnel Builder WordPress plugin flaw to sk­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8bb80681b1f9256cd00721f7d102abfccdc969b4bc4a30e0e119b5b7465d7af8
Enrichment time
2026-05-18T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 · Baitaphish