NGINX Rift CVE-2026-42945 — 18-Year-Old Bug Hands Attackers Your Web Server Without Auth
A heap buffer overflow in NGINX ngx_http_rewrite_module has been hiding in the codebase since 2008. CVE-2026-42945 (CVSS 9.2) lets unauthenticated attackers hijack any unpatched NGINX instance. With NGINX powering over 30% of the internet, patch immediately.