INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
NGINX Rift Vulnerability Exposed Affecting NGINX and F5 Products Worldwide
| 2026-05-19 10:12 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers actively exploited a high-severity security flaw in F5's NGINX web server software, dubbed Nginx Rift and tracked as CVE-2026-42945, just days after its publication. The vulnerability carries a CVSS score of 8.1 and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products. Approximately 5.7 million web servers are running potentially vulnerable NGINX versions, but the truly exploitable population is likely a tiny fraction of that. The exploit works by triggering a rare combination of settings on a server administrator's rewrite directive, allowing an unauthenticated attacker to send a heavily manipulated web request and crash the website in a denial-of-service (DoS) attack. By 16 May, network honeypots and canary systems flagged the first real-world attacks, highlighting the rapid escalation of the situation following the release of F5's official security advisory alongside a public GitHub attack script on 13 May 2026.
Technical Mitigations AI-generated
• CVE-2026-42945: Patch NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6.
• Use named captures instead of unnamed ones to mitigate the flaw in systems that cannot be updated immediately.
• Detect the exploit by monitoring for repeated crashes or denial-of-service (DoS) attacks on websites using NGINX.
• Block or hunt for the use of setarch -R command tools, which can force Address Space Layout Randomization (ASLR) off and enable remote code execution.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
pr•••••.php
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42945CVE-2026-42945
CVE-2026-40701CVE-2026-40701
CVE-2026-42946CVE-2026-42946
CVE-2026-42934CVE-2026-42934
Target & Sectors
Global Scope
Incident Timeline
May 2026
Threat actors are exploiting the CVE-2026-42945 vulnerability in NGINX and F5 products to achieve remote code execution through a heap buffer overflow in the rewrite module.
Click on any entity below to view its context and source!
infrastructure
1.31.0
Reportedly, F5 has fixed the issue in NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6.
infrastructure
1.30.1
Reportedly, F5 has fixed the issue in NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6.
infrastructure
Linux
Linux distributors for Ubuntu, Debian, and AlmaLinux have also started releasing fixes.
2026/05/19
Threat actors are actively exploiting the NGINX Rift vulnerability, tracked as CVE-2026-42945, in F5 NGINX products and potentially vulnerable web servers.
Click on any entity below to view its context and source!
infrastructure
5.7
…Exploitation timeline (source: Vulncheck)
Sizing Up the Actual Risk
A Censys query run by VulnCheck shows roughly 5.7 million web servers running potentially vulnerable NGINX versions, but the truly exploitable population is likely a tiny…
infrastructure
5.7 web servers
VulnCheck’s vulnerability researcher Patrick Garrity
reported
on social media, stating, “We’re seeing active exploitation of CVE-2026-42945 in F5 NGINX… on VulnCheck Canaries just days after the CVE was published.”
Exploitation timeline (sourc…
infrastructure
0.6.27
…is a heap-based buffer overflow (CWE-122) found inside the ngx_http_rewrite_module and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products, including the NGINX Ingress Con…
NGINX Open Source versions from 0.6.27 through 1.30.0 are affected, as are NGINX Plus R32 through R36.
infrastructure
1.30.0
NGINX Open Source versions from 0.6.27 through 1.30.0 are affected, as are NGINX Plus R32 through R36.
…ed buffer overflow (CWE-122) found inside the ngx_http_rewrite_module and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products, including the NGINX Ingress Controller and F5…
financial
$1 $ expression capture group
A server administrator must have set up a rewrite directive followed immediately by a second rewrite, if or set directive, and the rule must use an unnamed regular expression capture group ($1 or $2) pointing to a replacement string with a literal q…
The root of the problem lies in how NGINX handles rewrite directives that combine unnamed PCRE capture groups, the familiar $1, $2 syntax, with a replacement string containing a question mark, when followed by another rewrite, if, or set directive i…
Replacing unnamed captures ($1, $2) with named captures eliminates the vulnerable code path without requiring downtime.
financial
$2 $ familiar syntax
The root of the problem lies in how NGINX handles rewrite directives that combine unnamed PCRE capture groups, the familiar $1, $2 syntax, with a replacement string containing a question mark, when followed by another rewrite, if, or set directive i…
Tactical Metrics
Metrics
infrastructure
5.7
Software Version
Click for context!
…Exploitation timeline (source: Vulncheck)
Sizing Up the Actual Risk
A Censys query run by VulnCheck shows roughly 5.7 million web servers running potentially vulnerable NGINX versions, but the truly exploitable population is likely a tiny…
Metrics
infrastructure
5,700,000
Web Servers
VulnCheck’s vulnerability researcher Patrick Garrity
reported
on social media, stating, “We’re seeing active exploitation of CVE-2026-42945 in F5 NGINX… on VulnCheck Canaries just days after the CVE was published.”
Exploitation timeline (sourc…
Metrics
infrastructure
0.6.27
Software Version
…is a heap-based buffer overflow (CWE-122) found inside the ngx_http_rewrite_module and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products, including the NGINX Ingress Con…
NGINX Open Source versions from 0.6.27 through 1.30.0 are affected, as are NGINX Plus R32 through R36.
Metrics
infrastructure
1.30.0
Software Version
…ed buffer overflow (CWE-122) found inside the ngx_http_rewrite_module and affects NGINX Open Source versions 0.6.27 through 1.30.0, NGINX Plus versions R32 through R36, and several tied-in F5 products, including the NGINX Ingress Controller and F5…
NGINX Open Source versions from 0.6.27 through 1.30.0 are affected, as are NGINX Plus R32 through R36.
Metrics
infrastructure
1.31.0
Software Version
Reportedly, F5 has fixed the issue in NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6.
Metrics
infrastructure
1.30.1
Software Version
Reportedly, F5 has fixed the issue in NGINX Open Source versions 1.31.0 and 1.30.1, and NGINX Plus versions R36 P4 and R32 P6.
Metrics
infrastructure
Linux
Affected Product
Linux distributors for Ubuntu, Debian, and AlmaLinux have also started releasing fixes.
Metrics
financial
1
$ Expression Capture Group
A server administrator must have set up a rewrite directive followed immediately by a second rewrite, if or set directive, and the rule must use an unnamed regular expression capture group ($1 or $2) pointing to a replacement string with a literal q…
The root of the problem lies in how NGINX handles rewrite directives that combine unnamed PCRE capture groups, the familiar $1, $2 syntax, with a replacement string containing a question mark, when followed by another rewrite, if, or set directive i…
Replacing unnamed captures ($1, $2) with named captures eliminates the vulnerable code path without requiring downtime.
Metrics
financial
2
$ Familiar Syntax
The root of the problem lies in how NGINX handles rewrite directives that combine unnamed PCRE capture groups, the familiar $1, $2 syntax, with a replacement string containing a question mark, when followed by another rewrite, if, or set directive i…
Intelligence Sources
HackRead
2026-05-19
Security Affairs
2026-05-14
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
34x
organisation
Identified Entity
VulnCheck
entity
5x
infrastructure
Software Version
5.7
version
5x
timeline
Temporal Reference
13 May 2026
date
4x
vulnerability
Exploited CVE
CVE-2026-42945
cve
2x
tactic
Cyber Operation Type
Buffer Overflow
tactic
2x
general metric
Cvss V4
8
cvss v4
Contextual Telemetry
Context Block
6 METRICS
industry
Targeted Sector
Media
sector
infrastructure
Web Servers
5,700,000
web servers
vulnerability
CVSS Score
8
score
infrastructure
Affected Product
Linux
software
financial
$ Expression Capture Group
1
$ expression capture group
financial
$ Familiar Syntax
2
$ familiar syntax
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.