NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
2026-05-18T01:24:05Z•22d882bb9ba7fde6159ba56190d8bb38d81f17ec9612d4b96d10a40b00a9c35b
active-exploitationauthentication-bypasscheckout-skimmingcisa-kevcisco-sd-wanfragnesiafunnel-buildergemstuffergithub-token-breachgrafanaheap-buffer-overflowlinux-kernelmicrosoft-exchangenginxnode-ipcnpm-malwareprisonaiprivilege-escalationremote-code-executionrubygemssupply-chaintanstackturlawindows-zero-daywordpress
What happened
The feed highlights a surge of high-impact, actively exploited vulnerabilities and supply‑chain incidents. Key items: a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945, CVSS 9.2) is being exploited in the wild causing worker crashes and possible RCE; a maximum‑severity authentication bypass in Cisco Catalyst SD‑WAN Controller (CVE-2026-20182, CVSS 10.0) has been added to CISA KEV and exploited to gain admin access; on‑prem Microsoft Exchange (CVE-2026-42897, CVSS 8.1) is being exploited via crafted emails; PraisonAI (CVE-2026-44338) saw exploitation attempts within hours of dis
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 22d882bb9ba7fde6159ba56190d8bb38d81f17ec9612d4b96d10a40b00a9c35b
- Enrichment time
- 2026-05-18T01:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.