NGINX Heap Buffer Overflow RCE Exploited | MSSP Advisory

Critical
DateMay 17, 2026
📋Executive Summary
CVE-2026-42945 is a heap buffer overflow in NGINX's rewrite module affecting versions 0.6.27 through 1.30.0 with a CVSS score of 9.2. The vulnerability allows remote code execution and is already being exploited in the wild within days of disclosure. NGINX Plus and NGINX Open installations are both affected.
⚠️Why It Matters for MSSPs
Your own monitoring stack likely runs NGINX for web interfaces, reverse proxies, or load balancers, creating direct exposure to RCE attacks that could compromise your entire operation. Every client running NGINX web servers faces immediate exploitation risk, and if you stay silent while attacks succeed, you own the fallout conversation with angry customers.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.