- Joined
- Mar 6, 2020
- Messages
- 68
- Reaction score
- 18
Hi everyone,
I’m looking for some practical advice regarding the recent NGINX Rift vulnerability (CVE-2026-42945) and how it impacts 3CX.
From what I understand, it affects NGINX versions 0.6.27 through 1.30.0, but only if you have a very specific setup involving specific rewrite rules. We are currently running 3CX v20 Update 8 on Windows, and our bundled NGINX version is 1.26.3—which technically puts us in the affected range. Since active exploits are starting to pop up, we want to make sure we're covered.
We already checked our NGINX configuration files (C:\Program Files\3CX Phone System\Bin\nginx\conf) and couldn't find any rewrite rules that would trigger this flaw, as stated in the CVE.
That said, we’d love to get an official, vendor-supported answer on a couple of things:
Is the default 3CX configuration safe from being exploited by this?
What is the official game plan? Should we just wait for the next 3CX update with a patched NGINX version? -or- Are there any temporary workarounds we should apply, just to be safe?
Thanks.
I’m looking for some practical advice regarding the recent NGINX Rift vulnerability (CVE-2026-42945) and how it impacts 3CX.
From what I understand, it affects NGINX versions 0.6.27 through 1.30.0, but only if you have a very specific setup involving specific rewrite rules. We are currently running 3CX v20 Update 8 on Windows, and our bundled NGINX version is 1.26.3—which technically puts us in the affected range. Since active exploits are starting to pop up, we want to make sure we're covered.
We already checked our NGINX configuration files (C:\Program Files\3CX Phone System\Bin\nginx\conf) and couldn't find any rewrite rules that would trigger this flaw, as stated in the CVE.
That said, we’d love to get an official, vendor-supported answer on a couple of things:
Is the default 3CX configuration safe from being exploited by this?
What is the official game plan? Should we just wait for the next 3CX update with a patched NGINX version? -or- Are there any temporary workarounds we should apply, just to be safe?
Thanks.