Global Websites at Risk as AI Uncovers Critical NGINX Vulnerability
Artificial intelligence has achieved a landmark breakthrough in cybersecurity. The AI-powered security analysis system developed by the startup depthfirst autonomously uncovered a critical vulnerability in NGINX that had remained hidden for 18 yearsCVE-2026-42945 . This flaw, rated Critical (CVSS 9.2), impacts nearly one-third of websites globally, enabling attackers to perform remote code execution (RCE).

Key Vulnerability Details
Exposure Period: The vulnerability went undetected since its introduction in 2008, a span of 18 years.
Affected Versions: NGINX versions from 0.6.27 to 1.30.0.
Vulnerability Mechanism: The flaw resides in the rewrite module, stemming from a defect in the script engine's two-phase processing mechanism, which leads to a heap buffer overflow.
Patched Version: An official patch has been released. It is recommended to upgrade to the open-source version 1.31.0 or 1.30.1, or the corresponding commercial NGINX Plus release.
The Power of AI-Powered Security Analysis
This vulnerability was discovered by the San Francisco-based AI lab depthfirst. The system's capabilities have drawn significant industry attention:
High Efficiency: During just 6 hours of autonomous scanning, the system identified five security issues, including CVE-2026-42945 (four of which have been officially confirmed as remote memory corruption vulnerabilities).
Deep Comprehension: Unlike traditional tools, this AI understands complex business logic and cross-module interactions, uncovering vulnerabilities that even leading AI security tools had missed.
Data indicates approximately 19 million exposed NGINX instances are vulnerable. The United States (roughly 53.4 million affected instances, including historical data) and China (about 25.4 million) show the highest exposure levels. With the proof-of-concept (PoC) code now public, the security risk is severe. All enterprises and developers using NGINX are urged to immediately review their configuration files (particularly in scenarios using both rewrite and set directives) and complete version updates as soon as possible.
Related article
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Related Special Topic Recommendations
Comments (1)
0/500
Artificial intelligence has achieved a landmark breakthrough in cybersecurity. The AI-powered security analysis system developed by the startup depthfirst autonomously uncovered a critical vulnerability in NGINX that had remained hidden for 18 years

Key Vulnerability Details
Exposure Period: The vulnerability went undetected since its introduction in 2008, a span of 18 years.
Affected Versions: NGINX versions from 0.6.27 to 1.30.0.
Vulnerability Mechanism: The flaw resides in the rewrite module, stemming from a defect in the script engine's two-phase processing mechanism, which leads to a heap buffer overflow.
Patched Version: An official patch has been released. It is recommended to upgrade to the open-source version 1.31.0 or 1.30.1, or the corresponding commercial NGINX Plus release.
The Power of AI-Powered Security Analysis
This vulnerability was discovered by the San Francisco-based AI lab depthfirst. The system's capabilities have drawn significant industry attention:
High Efficiency: During just 6 hours of autonomous scanning, the system identified five security issues, including CVE-2026-42945 (four of which have been officially confirmed as remote memory corruption vulnerabilities).
Deep Comprehension: Unlike traditional tools, this AI understands complex business logic and cross-module interactions, uncovering vulnerabilities that even leading AI security tools had missed.
Data indicates approximately 19 million exposed NGINX instances are vulnerable. The United States (roughly 53.4 million affected instances, including historical data) and China (about 25.4 million) show the highest exposure levels. With the proof-of-concept (PoC) code now public, the security risk is severe. All enterprises and developers using NGINX are urged to immediately review their configuration files (particularly in scenarios using both rewrite and set directives) and complete version updates as soon as possible.
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation





Home






