NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

2026-05-17T19:24:25Zac9fc0bcaa647d07537eef5972d557bf466db9b0037b29989dcb12bf25dac792
CVE-2026-20182CVE-2026-42897CVE-2026-42945CVE-2026-44338CVE-2026-46300Cisco SD-WANClaw ChainExchange ServerFragnesiaFunnel BuilderGemStufferGrafanaKazuarNGINXOpenClawPraisonAIRubyGemsTanStackTurlaWindows zero-dayWooCommercecheckout skimmingnode-ipcsupply chain

What happened

A batch of active and high-impact security incidents and disclosures: a long‑undiscovered heap overflow in NGINX rewrite module (CVE-2026-42945, RCE/worker crashes) is being exploited in the wild; Cisco Catalyst SD‑WAN auth‑bypass (CVE-2026-20182, CVSS 10.0) has been added to CISA KEV and is actively exploited to gain admin access; on‑prem Exchange (CVE-2026-42897) is under active exploitation via crafted email; a PraisonAI auth bypass (CVE-2026-44338) was targeted within hours of disclosure; a new Linux kernel LPE (CVE-2026-46300, “Fragnesia”) and multiple Windows zero‑days were disclosed; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ac9fc0bcaa647d07537eef5972d557bf466db9b0037b29989dcb12bf25dac792
Enrichment time
2026-05-17T19:24:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.