Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 7 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Critical flaw in software powering a third of the internet is already being exploited – free checker now available

by Guru Writer
May 20, 2026
in News
Critical flaw in software powering a third of the internet is already being exploited – free checker now available
Share on FacebookShare on Twitter

A critical security vulnerability in NGINX, the web server software underpinning more than 30% of all websites globally, has been confirmed as actively exploited in the wild, less than a week after its public disclosure.

The flaw, tracked as CVE-2026-42945 and dubbed ‘NGINX Rift’, carries a severity score of 9.8 out of 10. It affects virtually every standard NGINX build released between 2008 and May 2026, an exposure window spanning 18 years.

NGINX’s developer, F5, issued an emergency patch on 13 May 2026, the same day the vulnerability was made public. A working proof-of-concept exploit was also published that day by security research group DepthFirst, and exploitation in the wild was confirmed within hours.

What the vulnerability does

The flaw lies in a component called ngx_http_rewrite_module, which handles URL rewriting, a standard feature used by virtually every NGINX installation. The bug was discovered through an AI-powered automated analysis of the NGINX source code conducted in April 2026.

In practical terms, the vulnerability allows an attacker to crash a target server with a single unauthenticated web request: no password, no login, no prior access required. In certain circumstances, it can allow an attacker to take full control of an affected system remotely.

Daniel Benechea, security manager at Pentest-Tools.com, said, “NGINX processes rewrite rules in two passes. The first calculates how much memory to allocate; the second does the actual writing. Under specific conditions, the second pass writes more data than the first reserved space. On a typical modern server, this causes a crash and restart loop, effectively a denial of service. On a system with a particular security feature disabled, it can hand an attacker control of the server.”

Because NGINX sits at the perimeter of so many internet-facing systems, handling web traffic for enterprise applications, API gateways, content delivery networks, and cloud services, a vulnerability at this layer has the potential to affect not just one organisation but every system behind it.

Patching is more complicated than it looks

F5 has released fixes across its product range. Affected organisations should upgrade to NGINX Open Source 1.30.1 (stable branch) or 1.31.0 (mainline), or NGINX Plus R36 P1. No backport patch is planned for older versions.

Security teams are, however, being warned that upgrading a primary NGINX installation may not be sufficient. Organisations running containerised applications, common across modern cloud infrastructure, may have copies of NGINX baked into container images that will not be updated automatically. Kubernetes ingress controllers, which frequently embed NGINX, require separate attention.

Benechea added, “Upgrade first. Then check your container images and Kubernetes ingress controllers separately. Upgrading your main NGINX install doesn’t automatically update those. For most teams, just upgrading is the simpler and safer path.”

For organisations that cannot patch immediately, F5 has documented a configuration-level workaround, but security teams note it requires manually auditing every rewrite rule across all configuration files, which is a significant undertaking for large or inherited deployments.

Free scanner released

Cybersecurity company Pentest-Tools.com has added detection for CVE-2026-42945 to its Network Vulnerability Scanner and is making it freely available with no account required. The scanner checks which version of NGINX is running on a given system and flags any instance within the vulnerable range.

The tool is available here: https://pentest-tools.com/network-vulnerability-scanning/cve-2026-42945-scanner-nginx-rift. Findings are labelled as unconfirmed, consistent with version-based detection, meaning a flagged result indicates a vulnerable version is present but does not confirm whether the specific trigger conditions are active in that system’s configuration.

A signal about the future of vulnerability research

The discovery of NGINX Rift carries a notable footnote: the flaw was found not by a human researcher but by an automated, AI-powered analysis of the NGINX source code. DepthFirst ran the analysis in April 2026 and disclosed the finding responsibly before publishing its technical write-up on the day F5 issued its patch.

“An 18-year-old flaw hiding in a module that ships by default in every NGINX build is exactly the kind of exposure that’s hard to find without automated analysis. That says something meaningful about where vulnerability research is heading; systematic coverage of codebases that have been running in production for years without close scrutiny,” Benechea concludes.

The finding raises questions about how many similar long-standing flaws may remain undiscovered in widely deployed open-source software, and whether automated tooling will increasingly be the means by which they surface.

What organisations should do now.

  1. Patch immediately. Upgrade to NGINX Open Source 1.30.1 / 1.31.0 or NGINX Plus R36 P1.
  2. Audit container images. Check for NGINX binaries embedded in container images separately from your primary installation.
  3. Check Kubernetes ingress controllers. These frequently embed NGINX and require independent patching.
  4. Use the free scanner. Pentest-Tools.com’s no-login scanner can confirm whether exposed versions are present on your external attack surface.
ShareTweet
Previous Post

Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

Next Post

Industry Reacts to Verizon DBIR 2026 as Vulnerability Exploitation Takes Top Spot

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol