people · May 17, 2026
Axonius Publishes NGINX Rift CVE-2026-42945 Detection and Remediation Guidance
Share the canonical public link.
Axonius released guidance on May 14, 2026, for identifying and fixing assets vulnerable to NGINX Rift (CVE-2026-42945). The vulnerability is a critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 and NGINX Plus R32 through R36, carrying a CVSS v4.0 score of 9.2 and enabling unauthenticated remote code execution or denial of service. Axonius provides specific queries to surface vulnerable NGINX instances via its Asset Cloud platform, including searches for CVE-2026-42945 in security findings and for unpatched software versions on internet-exposed systems. The guidance prioritizes perimeter assets such as proxies, API gateways, and Kubernetes ingress controllers. NGINX Rift has existed since 2008 and affects the most popular web server software.