#cybersecurity #threatintelligence #riskmanagement #infosecurity | Patrick Garrity 👾🛹💙
We're seeing active exploitation of CVE-2026-42945 in F5 NGINX, a heap buffer overflow affecting both NGINX Plus and NGINX Open Source on VulnCheck Canaries just days after the CVE was published.
Yesterday, the VulnCheck Initial Access team noted in our release notes: "An unauthenticated attacker can crash the NGINX worker process by sending crafted HTTP requests. On servers with ASLR disabled — which, of course, is extremely unlikely — code execution is possible. A further caveat is that the target server must be running a specific rewrite configuration to be vulnerable, so not every NGINX instance is exploitable. Our Censys query surfaces roughly 5.7M internet-exposed NGINX servers running a potentially vulnerable version, though the truly exploitable population is likely a much smaller subset."
Full release notes are here: https://lnkd.in/eDxGTabZ
#cybersecurity #threatintelligence #riskmanagement #infosecurity
www.linkedin.com
Comments (0)