CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-42945: NGINX Rift Heap Overflow

June 25, 2026

A heap overflow in NGINX's expression-evaluation code, disclosed in May 2026. Similar class of flaw as CVE-2026-42533, involving two-pass script engine. Exploit went public within days and drew active exploitation.