Two bytes to RCE: chaining rift + PoolSlip into an ASLR-independent nginx 1.30.0 exploit (opens in new tab)
Chaining nginx PoolSlip (CVE-2026-9256) + Rift (CVE-2026-42945) into an ASLR-independent RCE on the stock nginx:1.30.0 image; leak + 2-byte partial overwrite to system().
Read the original article