Cybersecurity researchers disclose multiple vulnerabilities affecting NGINX Plus and NGINX Open, including a long-unfixed flaw in the ngx_http_rewrite_module. One issue, identified as CVE-2026-42945, is reported as a heap buffer overflow with a CVSS v4 score of 9.2. Researchers say the flaw has been present for around 18 years and was not previously detected.

According to reports, the vulnerability can be exploited by an attacker to cause denial-of-service conditions. Under certain circumstances, exploitation may also lead to remote code execution. The reports also state that the affected code path can be reached without authentication, depending on the target configuration.

The vulnerability was discovered by a researcher associated with the finding described in the reports, and separate coverage notes it was found using an autonomous scanning system. Both outlets describe the flaw as serious and emphasize that successful exploitation depends on the specific conditions on the server. The disclosures prompt users to review vendor guidance and apply available fixes or mitigations where applicable.