
18-Year NGINX Bug Exposes 1/3 of the Web
CVE-2026-42945 is a critical heap overflow in NGINX — CVSS 9.8, zero credentials required, 18 years undetected — affecting roughly 34% of all websites globally. F5 patched fast; the real challenge is remediation sprawl across fragmented Docker images, Kubernetes ingress controllers, and managed CDN configurations.









