F5 NGINX Emergency Patches for Critical 'NGINX Rift' RCE CVE-2026-42945
F5 has issued emergency patches for CVE-2026-42945, a critical heap buffer overflow vulnerability within the NGINX rewrite module, known as "NGINX Rift." Discovered through AI-driven LLM grounding, this flaw has persisted in legacy code for approximately 18 years. The vulnerability enables unauthenticated Remote Code Execution (RCE) and Denial of Service (DoS) by exploiting specific 'rewrite' rule syntax. Given NGINX's ubiquity as a reverse proxy, API gateway, and edge load balancer, the attack surface is massive, posing a significant risk of complete system compromise and service disruption for critical internet-facing infrastructure.
Edge-to-Core Escalation: Nation-State Actors Weaponize EOL F5 BIG-IP Appliances
Nation-state threat actors are pivoting from traditional endpoint attacks to "Edge-to-Core" escalation, weaponizing unpatched or End-of-Life (EOL) F5 BIG-IP appliances to bypass perimeter defenses. By exploiting the implicit trust between edge devices and internal infrastructure, attackers are successfully pivoting through internal SaaS applications to achieve full Identity and Active Directory compromise.