CVE

CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buf

Exploitation IoCs 3

Domain corepack[.]org
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93

MITRE ATT&CK TTPs 13

Source Articles

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
A critical vulnerability in NGINX, tracked as CVE-2026-42533, allows remote unauthenticated attackers to trigger a heap buffer overflow via crafted HTTP requests, potentially leading to denial of service or remote code execution. The flaw exists in NGINX's script engine under specific configurations involving regex-based maps and capture overwrites. Exploitation may bypass ASLR, increasing the risk even on default systems, though no public exploits have been observed yet. F5 has released patches for core NGINX and NGINX Plus, but downstream products lack updated builds at the time of publication.
hacker-news Jul 19, 2026