Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 17, 2026 (about 4 months ago).

people · May 17, 2026

Axonius Publishes NGINX Rift CVE-2026-42945 Detection and Remediation Guidance

Share the canonical public link.

Share as image

Axonius released guidance on May 14, 2026, for identifying and fixing assets vulnerable to NGINX Rift (CVE-2026-42945). The vulnerability is a critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 and NGINX Plus R32 through R36, carrying a CVSS v4.0 score of 9.2 and enabling unauthenticated remote code execution or denial of service. Axonius provides specific queries to surface vulnerable NGINX instances via its Asset Cloud platform, including searches for CVE-2026-42945 in security findings and for unpatched software versions on internet-exposed systems. The guidance prioritizes perimeter assets such as proxies, API gateways, and Kubernetes ingress controllers. NGINX Rift has existed since 2008 and affects the most popular web server software.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence