An 18-year-old NGINX flaw can lead to remote code execution

A vulnerability that has been present in NGINX for 18 years has been disclosed. The flaw is tracked as CVE-2026-42945 and can, under specific conditions, allow remote code execution. F5 has published its own security article on the issue, and the researchers behind the finding have described the technique in detail.

What this means for your organisation

NGINX sits in front of a large share of Norwegian websites and APIs, often as a load balancer or the entry point from the internet. When a component in that position can be exploited, the exposure is not one website but the single point all traffic passes through. Many organisations also run NGINX inside products bought from a vendor, without it appearing in any inventory. In that case, patching may not be yours to do.

Berigo recommends

  • Map where NGINX actually runs in your estate, including versions bundled with off-the-shelf products and container images.
  • Follow the F5 security article and update internet-exposed instances first.
  • Send a specific enquiry to vendors shipping solutions with NGINX underneath, and ask for a written answer on whether the product is affected.
  • Verify that you have logging from the reverse proxy layer that can genuinely support an investigation afterwards.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch