INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

NGINX Rift Vulnerability Exposed Affecting NGINX and F5 Products Worldwide

| 2026-05-19 10:12 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers actively exploited a high-severity security flaw in F5's NGINX web server software, dubbed Nginx Rift and tracked as CVE-2026-42945, just days after its publication. The vulnerability carries a CVSS score of 8.1 and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products. Approximately 5.7 million web servers are running potentially vulnerable NGINX versions, but the truly exploitable population is likely a tiny fraction of that. The exploit works by triggering a rare combination of settings on a server administrator's rewrite directive, allowing an unauthenticated attacker to send a heavily manipulated web request and crash the website in a denial-of-service (DoS) attack. By 16 May, network honeypots and canary systems flagged the first real-world attacks, highlighting the rapid escalation of the situation following the release of F5's official security advisory alongside a public GitHub attack script on 13 May 2026.
Technical Mitigations AI-generated
• CVE-2026-42945: Patch NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6. • Use named captures instead of unnamed ones to mitigate the flaw in systems that cannot be updated immediately. • Detect the exploit by monitoring for repeated crashes or denial-of-service (DoS) attacks on websites using NGINX. • Block or hunt for the use of setarch -R command tools, which can force Address Space Layout Randomization (ASLR) off and enable remote code execution.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

pr•••••.php
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42945CVE-2026-42945 CVE-2026-40701CVE-2026-40701 CVE-2026-42946CVE-2026-42946 CVE-2026-42934CVE-2026-42934
Target & Sectors
Global Scope
Incident Timeline
‎May 2026
Threat actors are exploiting the CVE-2026-42945 vulnerability in NGINX and F5 products to achieve remote code execution through a heap buffer overflow in the rewrite module.
infrastructure 1.31.0
infrastructure 1.30.1
infrastructure Linux
‎2026/05/19
Threat actors are actively exploiting the NGINX Rift vulnerability, tracked as CVE-2026-42945, in F5 NGINX products and potentially vulnerable web servers.
infrastructure 5.7
infrastructure 5.7 web servers
infrastructure 0.6.27
infrastructure 1.30.0
financial $1 $ expression capture group
financial $2 $ familiar syntax
Tactical Metrics
Metrics
infrastructure
‎5.7
Software Version
Metrics
infrastructure
5,700,000
Web Servers
Metrics
infrastructure
‎0.6.27
Software Version
Metrics
infrastructure
‎1.30.0
Software Version
Metrics
infrastructure
‎1.31.0
Software Version
Metrics
infrastructure
‎1.30.1
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
financial
1
$ Expression Capture Group
Metrics
financial
2
$ Familiar Syntax