nginx Rift: 18-Year-Old Bug Enables No-Auth RCE Now
CVE-2026-42945 gives attackers unauthenticated RCE on nginx with one HTTP request. A PoC is already public. Here's what's broken and how to fix ...
Privacy, vulnerabilities, authentication, and cybersecurity