<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability on Pfisterer Consulting</title><link>https://pfisterer.xyz/en/tags/vulnerability/</link><description>Recent content in Vulnerability on Pfisterer Consulting</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 15 May 2026 07:00:00 +0200</lastBuildDate><atom:link href="https://pfisterer.xyz/en/tags/vulnerability/index.xml" rel="self" type="application/rss+xml"/><item><title>Six Hours, Eighteen Years: What NGINX Rift Tells the Mittelstand</title><link>https://pfisterer.xyz/en/news/nginx-rift-18-jahre-ki-audit-mittelstand/</link><pubDate>Fri, 15 May 2026 07:00:00 +0200</pubDate><guid>https://pfisterer.xyz/en/news/nginx-rift-18-jahre-ki-audit-mittelstand/</guid><description>&lt;p&gt;On May 13, 2026, F5 and security researcher depthfirst publish a disclosure with weight behind it. CVE-2026-42945, codenamed &lt;strong&gt;NGINX Rift&lt;/strong&gt;, CVSS 9.2. Unauthenticated remote code execution in the &lt;code&gt;ngx_http_rewrite_module&lt;/code&gt; of NGINX. Affected: all open-source versions from 0.6.27 through 1.30.0 and NGINX Plus R32 through R36. The bug has been in the code since 2008. Eighteen years.&lt;/p&gt;
&lt;p&gt;The actual punchline sits in the disclosure footnote. The bug was not found by a human researcher. It was found by an autonomous AI analysis system. Six hours of runtime against one of the most thoroughly reviewed open-source codebases on the planet. This is the direct confirmation of the thesis I sketched on May 13 in the article on the &lt;a href="https://pfisterer.xyz/en/news/claude-mythos-firefox-glasswing-mittelstand/"&gt;Mythos Glasswing asymmetry&lt;/a&gt; as something coming. It arrived a week later.&lt;/p&gt;</description></item></channel></rss>